CVE Tools

Pre-Authentication SQL Injection in FortiClient EMS 7.4.4 - CVE-2026-21643

Bishop FoxBy John Untz14 min read

Reported exploitedFortiClient EMS
Read at Bishop Fox

Below is the opening; the full story is at Bishop Fox.

From Bishop Fox

TL;DR

Bishop Fox researchers expanded on Fortinet’s disclosure of CVE-2026-21643 by identifying practical exploitation paths. Our analysis shows attackers can abuse the publicly accessible /api/v1/init_consts endpoint to trigger the SQL injection before authentication. Because this endpoint returns database error messages and has no lockout protections, attackers can rapidly extract sensitive data from vulnerable FortiClient EMS 7.4.4 multi-tenant deployments.…

Continue at Bishop Fox

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store