SQL Injection Vulnerability in Fortinet FortiClientEMS
CVE-2026-39809
6.2MEDIUM
What is CVE-2026-39809?
Fortinet FortiClientEMS versions from 7.0 to 7.4.5 are susceptible to an SQL injection vulnerability due to improper neutralization of special elements used in SQL commands. An attacker could exploit this flaw to execute unauthorized code or commands, leading to potential data breaches and compromised system integrity. It is crucial to update to the latest patched versions to mitigate the risk and secure your environments.
Affected Version(s)
FortiClientEMS 7.4.3 <= 7.4.4
FortiClientEMS 7.4.0 <= 7.4.1