CVE-2026-39810
A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5 may allow attacker to information disclosure via decrypting database dump.
Severity
Medium 5.2
CVSS 3.1
Exploited
Not listed
EPSS
0.001
1.0th percentile
Discovered by
Vendor
Vendor advisory field
Published
Apr 14, 2026
Assigned by fortinet
Description
A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5 may allow attacker to information disclosure via decrypting database dump.
Weakness: CWE-321
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiClient | Endpoint / EDR | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiClientEMS
Credit
Internally discovered and reported by David Maciejak of Fortinet Product Security team.
Vendor remediation
Upgrade to FortiClientEMS version 7.4.6 or above