CVE-2026-39809
published 2026-04-14CVE-2026-39809: A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5…
PriorityP336medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.13%
3.2th percentile
A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5, FortiClientEMS 7.2.0 through 7.2.12, FortiClientEMS 7.0 all versions may allow attacker to execute unauthorized code or commands via sending crafted requests
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | forticlientems | — | — |
| fortinet | forticlientems | 7.0.0 – 7.0.13 | — |
| fortinet | forticlientems | >= 7.2.0 < 7.2.13 | 7.2.13 |
| fortinet | forticlientems | >= 7.4.0 < 7.4.6 | 7.4.6 |
| fortinet | forticlientems | 7.4.0 – 7.4.1 | — |
| fortinet | forticlientems | 7.4.3 – 7.4.4 | — |
| fortinet | fortinet | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g2q7-p5pr-qxqg: A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7
ghsa_unreviewed·2026-04-14
CVE-2026-39809 [MEDIUM] CWE-89 GHSA-g2q7-p5pr-qxqg: A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7
A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5, FortiClientEMS 7.2.0 through 7.2.12, FortiClientEMS 7.0 all versions may allow attacker to execute unauthorized code or commands via sending crafted requests
Fortinet
Multiple SQL Injections
vendor_fortinet·2026-04-14·CVSS 6.7
CVE-2026-39809 [MEDIUM] CWE-89 Multiple SQL Injections
FG-IR-26-102: Multiple SQL Injections
A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5, FortiClientEMS 7.2.0 through 7.2.12, FortiClientEMS 7.0 all versions may allow attacker to execute unauthorized code or commands via sending crafted requests
CVEs: CVE-2026-39809
CWEs: CWE-89
CVSS: 6.7 (medium)
Affected products: FortiClientEMS, Fortinet
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-14
Published