CVE-2026-21643 – Critical Pre‑Auth SQL Injection in FortiClient EMS
Key takeaways
- Critical pre‑authentication SQL injection in FortiClient Endpoint Management Server (EMS) 7.4.4.
- Unauthenticated attackers can inject arbitrary SQL, leading to full database dump or remote code execution via PostgreSQL.
- Active exploitation observed since late March 2026, with dozens of attempts per day.
- Vulnerable only when the multi‑tenant “Sites” feature is enabled; other versions are not affected.
- Immediate patch to FortiClient EMS 7.4.5 or later, or block public access.
Overview
The vulnerability identified as CVE-2026-21643 is a pre‑authentication SQL injection flaw in Fortinet’s FortiClient Endpoint Management Server (EMS) 7.4.4. The issue resides in the handling of the Site HTTP header on the public API endpoint /api/v1/init_consts (and the login endpoint). Because the header value is concatenated directly into a PostgreSQL query with super‑user privileges, an unauthenticated attacker can execute arbitrary SQL statements.
Threat‑intel feeds show a rapid rise in exploit activity:
- March 30 2026: 25 reports of active exploitation and a publicly released PoC.
- Early April 2026: 12‑15 daily exploitation reports, with multiple PoCs and exploit scripts circulating.
- Overall: 123 mentions across 17 days, with a clear spike after the first public exploit on March 28.
For a live view of the signal timeline, see the VulnSocial CVE page.
Technical Details
The vulnerable code builds a SQL statement similar to:
SELECT * FROM sites WHERE id = '<Site header value>';
When the Site header contains a malicious payload, the query is executed with the PostgreSQL super‑user role. An attacker can:
- Dump the entire database (
SELECT * FROM pg_catalog.pg_tables;). - Extract schema and credentials.
- Trigger OS commands using PostgreSQL extensions such as
COPY FROM PROGRAMorpg_exec, achieving remote code execution (RCE).
A minimal proof‑of‑concept request looks like:
POST /api/v1/init_consts HTTP/1.1
Host: ems.example.com
Site: 1' UNION SELECT null, null, pg_sleep(5) --
Content-Type: application/json
Content-Length: 0
{}
The payload is processed before authentication (PR:N), and the impact scores are C:H/I:H/A:H, reflecting total compromise of confidentiality, integrity, and availability.
Severity & Impact
| Metric | Value |
|---|---|
| CVSS | CVSS 9.8 (Critical) |
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CWE | CWE‑89 (SQL Injection) |
The high CVSS score reflects the remote, unauthenticated nature of the attack and the potential for full system compromise.
Affected Products
- FortiClient EMS 7.4.4 with the multi‑tenant “Sites” feature enabled.
- Versions 7.2.x, 8.0.x, and deployments without Sites are not vulnerable.
For a complete list of affected versions and configurations, see the VulnSocial CVE page.
What to Do
- Identify exposed EMS instances – scan for internet‑facing hosts responding to
FortiClient EMSbanners (e.g., Shodan, internal asset inventory). - Verify version and configuration – confirm whether the instance runs 7.4.4 and has the Sites feature enabled.
- Block public access – apply firewall rules or network segmentation to restrict the EMS API to trusted internal networks.
- Monitor for exploitation attempts – look for anomalous
Siteheader values, SQL error messages in web server logs, or unexpected PostgreSQL activity. - Leverage threat‑intel feeds – track real‑time indicators on the VulnSocial CVE page for new exploit tools or PoCs.
Remediation & Mitigation
- Patch – upgrade to FortiClient EMS 7.4.5 or later, which removes the vulnerable code path. See the FortiGuard advisory for patch details.
- If immediate upgrade is not possible, disable the Sites feature to eliminate the vulnerable code path.
- Restrict the EMS API – enforce inbound firewall rules that only allow trusted IP ranges.
- Deploy a Web Application Firewall (WAF) rule to drop requests containing suspicious
Siteheader patterns (e.g., containing single quotes orUNION). - Audit PostgreSQL logs for unexpected commands such as
COPY FROM PROGRAMor large data exfiltration queries. - Conduct a post‑remediation scan to confirm the vulnerability is no longer present.
Bottom Line
CVE-2026-21643 is a critical pre‑auth SQL injection in FortiClient EMS 7.4.4 that is already being actively exploited. The only effective mitigation is to patch to 7.4.5+ or, as a temporary measure, lock down the EMS API and disable the Sites feature. Organizations with internet‑exposed EMS deployments should treat this as a top priority.
References
- FortiGuard advisory: https://fortiguard.fortinet.com/psirt/FG-IR-25-1142
- VulnSocial CVE overview: https://vulnsocial.com/cve/CVE-2026-21643
- VulnSocial home: https://vulnsocial.com
#CVE #Critical #SQLi #RCE #Fortinet #FortiClientEMS #CVE202621643
