Multiple SQL Injections

Summary

An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiClientEMS may allow an authenticated attacker to run arbitrary SQL queries on the database via sending crafted requests.

Version Affected Solution
FortiClientEMS 7.4 7.4.0 through 7.4.5 Upgrade to 7.4.6 or above
FortiClientEMS 7.2 7.2.0 through 7.2.12 Upgrade to 7.2.13 or above
FortiClientEMS 7.0 7.0 all versions Migrate to a fixed release

Fortinet remediated this issue in FortiClient Cloud and hence customers do not need to perform any action.
Fortinet remediated this issue in FortiSASE and hence customers do not need to perform any action.

Acknowledgement

Internally discovered and reported by David Maciejak, Gwendal Guegniaud, Loic Pantano of Fortinet Product Security team.

Timeline

2026-04-14: Initial publication