Pre-Authentication SQL Injection in FortiClient EMS 7.4.4 - CVE-2026-21643
Reported exploitedFortiClient EMSBelow is the opening; the full story is at Bishop Fox.
From Bishop Fox
TL;DR
Bishop Fox researchers expanded on Fortinet’s disclosure of CVE-2026-21643 by identifying practical exploitation paths. Our analysis shows attackers can abuse the publicly accessible
/api/v1/init_constsendpoint to trigger the SQL injection before authentication. Because this endpoint returns database error messages and has no lockout protections, attackers can rapidly extract sensitive data from vulnerable FortiClient EMS 7.4.4 multi-tenant deployments.…
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.