CVE-2026-35616
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
Severity
Critical 9.1
CVSS 3.1
Exploited
Yes — in CISA KEV
Added Apr 6, 2026
EPSS
0.907
99.8th percentile
Discovered by
Third party
Vendor advisory field
Published
Apr 4, 2026
Assigned by fortinet
Description
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
Weakness: CWE-284
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiClient | Endpoint / EDR | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiClientEMS
Credit
Fortinet is pleased to thank Simo Kohonen from Defused and Nguyen Duc Anh for reporting this vulnerability under responsible disclosure.
Vendor remediation
Upgrade to upcoming FortiClientEMS version 8.0.0 or above Upgrade to FortiClientEMS version 7.4.7 or above