CVE-2026-35616

A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

Severity
Critical 9.1
CVSS 3.1
Exploited
Yes — in CISA KEV
Added Apr 6, 2026
EPSS
0.907
99.8th percentile
Discovered by
Third party
Vendor advisory field
Published
Apr 4, 2026
Assigned by fortinet

Description

A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

Weakness: CWE-284

Affected products

Vendor Product Category Matched by
Fortinet FortiClient Endpoint / EDR cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiClientEMS

Credit

Fortinet is pleased to thank Simo Kohonen from Defused and Nguyen Duc Anh for reporting this vulnerability under responsible disclosure.

Vendor remediation

Upgrade to upcoming FortiClientEMS version 8.0.0 or above Upgrade to FortiClientEMS version 7.4.7 or above

Something wrong here?