Vulnerability Details CVE-2026-39809
A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5, FortiClientEMS 7.2.0 through 7.2.12, FortiClientEMS 7.0 all versions may allow attacker to execute unauthorized code or commands via sending crafted requests
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 7.8%
CVSS Severity
CVSS v3 Score 6.7
Products affected by CVE-2026-39809
-
cpe:2.3:a:fortinet:forticlientems:7.0.0
-
cpe:2.3:a:fortinet:forticlientems:7.0.1
-
cpe:2.3:a:fortinet:forticlientems:7.0.10
-
cpe:2.3:a:fortinet:forticlientems:7.0.11
-
cpe:2.3:a:fortinet:forticlientems:7.0.12
-
cpe:2.3:a:fortinet:forticlientems:7.0.13
-
cpe:2.3:a:fortinet:forticlientems:7.0.2
-
cpe:2.3:a:fortinet:forticlientems:7.0.3
-
cpe:2.3:a:fortinet:forticlientems:7.0.4
-
cpe:2.3:a:fortinet:forticlientems:7.0.5
-
cpe:2.3:a:fortinet:forticlientems:7.0.6
-
cpe:2.3:a:fortinet:forticlientems:7.0.7
-
cpe:2.3:a:fortinet:forticlientems:7.0.8
-
cpe:2.3:a:fortinet:forticlientems:7.0.9
-
cpe:2.3:a:fortinet:forticlientems:7.2.0
-
cpe:2.3:a:fortinet:forticlientems:7.2.1
-
cpe:2.3:a:fortinet:forticlientems:7.2.10
-
cpe:2.3:a:fortinet:forticlientems:7.2.12
-
cpe:2.3:a:fortinet:forticlientems:7.2.2
-
cpe:2.3:a:fortinet:forticlientems:7.2.3
-
cpe:2.3:a:fortinet:forticlientems:7.2.4
-
cpe:2.3:a:fortinet:forticlientems:7.2.5
-
cpe:2.3:a:fortinet:forticlientems:7.2.6
-
cpe:2.3:a:fortinet:forticlientems:7.2.7
-
cpe:2.3:a:fortinet:forticlientems:7.2.8
-
cpe:2.3:a:fortinet:forticlientems:7.2.9
-
cpe:2.3:a:fortinet:forticlientems:7.4.0
-
cpe:2.3:a:fortinet:forticlientems:7.4.1
-
cpe:2.3:a:fortinet:forticlientems:7.4.3
-
cpe:2.3:a:fortinet:forticlientems:7.4.4
-
cpe:2.3:a:fortinet:forticlientems:7.4.5