CRITICAL
CVE-2026-35616
CVSS
9.8
KEV
Description
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
Summary dbcve.org
Improper access control in Fortinet FortiClientEMS versions 7.4.5 through 7.4.6 allows unauthenticated attackers to execute arbitrary code or commands via specially crafted HTTP requests. This is a critical remote code execution vulnerability with no authentication required.
Mitigation
Upgrade FortiClientEMS to a patched version beyond 7.4.6. If immediate patching is not feasible, restrict network access to the EMS management interface to trusted sources only.
Weakness (CWE)
CWE-284
Improper Access Control
EPSS Score
90.75%
Probability of exploitation in next 30 days
99.8th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.