CVE-2026-21643

Description

An improper neutralization of special elements used in an sql command (sql injection) vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
33.907

Associated Vulnerability

VulnerabilityOS Platform
Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability (CVE-2026-21643)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234