PT-2026-6694 · Fortinet · Forticlientems

CVE-2026-21643

·

Published

2026-02-06

·

Updated

2026-06-30

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FortiClient EMS versions 7.0.1 through 7.0.13 FortiClient EMS versions 7.2.0 through 7.2.2 FortiClient EMS version 7.4.4
Description An improper neutralization of special elements used in an SQL command (SQL injection) exists in the web interface of the FortiClient Enterprise Management Server (EMS). The issue resides in the FCT DAS.exe (Data Analytics Service), which fails to sanitize the messaging parameter in incoming HTTP requests. An unauthenticated remote attacker can exploit this by sending specially crafted HTTP requests to the FCT DAS diagnostic service to inject malicious SQL commands. Because the underlying database often runs with high privileges, this can be escalated to full operating system command execution via the xp cmdshell stored procedure, allowing the attacker to gain a persistent SYSTEM shell on the management server. This flaw has been actively exploited by ransomware groups, including those deploying the Medusa strain, to pivot from the management server to all managed endpoints.
Recommendations Update FortiClient EMS versions 7.0.1 through 7.0.13 to version 7.0.14. Update FortiClient EMS versions 7.2.0 through 7.2.2 to version 7.2.3 or later. At the moment, there is no information about a newer version that contains a fix for version 7.4.4. Restrict access to management ports 443 and 10443 to trusted administrative IP addresses only.

Exploit

Fix

LPE

RCE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-01492
CVE-2026-21643

Affected Products

Forticlientems