Fortinet FortiClientEMS SQL Injection Vulnerability Allowing Unauthorized Code Execution

Vulnerability

A vulnerability allowing SQL injection has been identified in Fortinet FortiClientEMS versions 7.4.0 to 7.4.5, 7.2.0 to 7.2.12, and all versions of 7.0. This vulnerability arises from improper neutralization of special elements used in SQL commands, which may enable an authenticated attacker to execute arbitrary SQL queries on the database by sending crafted requests.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of SQL commands, potentially allowing attackers to manipulate the database or execute additional malicious actions.

Remediation

Users of Fortinet FortiClientEMS 7.4 should upgrade to version 7.4.6 or above. Users of Fortinet FortiClientEMS 7.2 should upgrade to version 7.2.13 or above. Users of Fortinet FortiClientEMS 7.0 should migrate to a fixed release.

Added: Apr 14, 2026, 4:53 PM
Updated: Apr 14, 2026, 4:53 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
2.5
exploitability
4.9
remediation
7.7
relevance
5.9
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.