CVE-2026-21643 – Critical Pre‑Auth SQL Injection in FortiClient EMS

Key takeaways

  • Critical pre‑authentication SQL injection in FortiClient Endpoint Management Server (EMS) 7.4.4.
  • Unauthenticated attackers can inject arbitrary SQL, leading to full database dump or remote code execution via PostgreSQL.
  • Active exploitation observed since late March 2026, with dozens of attempts per day.
  • Vulnerable only when the multi‑tenant “Sites” feature is enabled; other versions are not affected.
  • Immediate patch to FortiClient EMS 7.4.5 or later, or block public access.

Overview

The vulnerability identified as CVE-2026-21643 is a pre‑authentication SQL injection flaw in Fortinet’s FortiClient Endpoint Management Server (EMS) 7.4.4. The issue resides in the handling of the Site HTTP header on the public API endpoint /api/v1/init_consts (and the login endpoint). Because the header value is concatenated directly into a PostgreSQL query with super‑user privileges, an unauthenticated attacker can execute arbitrary SQL statements.

Threat‑intel feeds show a rapid rise in exploit activity:

  • March 30 2026: 25 reports of active exploitation and a publicly released PoC.
  • Early April 2026: 12‑15 daily exploitation reports, with multiple PoCs and exploit scripts circulating.
  • Overall: 123 mentions across 17 days, with a clear spike after the first public exploit on March 28.

For a live view of the signal timeline, see the VulnSocial CVE page.


Technical Details

The vulnerable code builds a SQL statement similar to:

SELECT * FROM sites WHERE id = '<Site header value>';

When the Site header contains a malicious payload, the query is executed with the PostgreSQL super‑user role. An attacker can:

  • Dump the entire database (SELECT * FROM pg_catalog.pg_tables;).
  • Extract schema and credentials.
  • Trigger OS commands using PostgreSQL extensions such as COPY FROM PROGRAM or pg_exec, achieving remote code execution (RCE).

A minimal proof‑of‑concept request looks like:

POST /api/v1/init_consts HTTP/1.1
Host: ems.example.com
Site: 1' UNION SELECT null, null, pg_sleep(5) --
Content-Type: application/json
Content-Length: 0

{}

The payload is processed before authentication (PR:N), and the impact scores are C:H/I:H/A:H, reflecting total compromise of confidentiality, integrity, and availability.


Severity & Impact

MetricValue
CVSSCVSS 9.8 (Critical)
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWECWE‑89 (SQL Injection)

The high CVSS score reflects the remote, unauthenticated nature of the attack and the potential for full system compromise.


Affected Products

  • FortiClient EMS 7.4.4 with the multi‑tenant “Sites” feature enabled.
  • Versions 7.2.x, 8.0.x, and deployments without Sites are not vulnerable.

For a complete list of affected versions and configurations, see the VulnSocial CVE page.


What to Do

  • Identify exposed EMS instances – scan for internet‑facing hosts responding to FortiClient EMS banners (e.g., Shodan, internal asset inventory).
  • Verify version and configuration – confirm whether the instance runs 7.4.4 and has the Sites feature enabled.
  • Block public access – apply firewall rules or network segmentation to restrict the EMS API to trusted internal networks.
  • Monitor for exploitation attempts – look for anomalous Site header values, SQL error messages in web server logs, or unexpected PostgreSQL activity.
  • Leverage threat‑intel feeds – track real‑time indicators on the VulnSocial CVE page for new exploit tools or PoCs.

Remediation & Mitigation

  1. Patch – upgrade to FortiClient EMS 7.4.5 or later, which removes the vulnerable code path. See the FortiGuard advisory for patch details.
  2. If immediate upgrade is not possible, disable the Sites feature to eliminate the vulnerable code path.
  3. Restrict the EMS API – enforce inbound firewall rules that only allow trusted IP ranges.
  4. Deploy a Web Application Firewall (WAF) rule to drop requests containing suspicious Site header patterns (e.g., containing single quotes or UNION).
  5. Audit PostgreSQL logs for unexpected commands such as COPY FROM PROGRAM or large data exfiltration queries.
  6. Conduct a post‑remediation scan to confirm the vulnerability is no longer present.

Bottom Line

CVE-2026-21643 is a critical pre‑auth SQL injection in FortiClient EMS 7.4.4 that is already being actively exploited. The only effective mitigation is to patch to 7.4.5+ or, as a temporary measure, lock down the EMS API and disable the Sites feature. Organizations with internet‑exposed EMS deployments should treat this as a top priority.


References

#CVE #Critical #SQLi #RCE #Fortinet #FortiClientEMS #CVE202621643