CRITICAL

CVE-2026-35616

Fortinet Forticlientems 2026-04-04 CVSS v3.1
CVSS
9.8
KEV

Description

A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

Summary dbcve.org

Improper access control in Fortinet FortiClientEMS versions 7.4.5 through 7.4.6 allows unauthenticated attackers to execute arbitrary code or commands via specially crafted HTTP requests. This is a critical remote code execution vulnerability with no authentication required.

Mitigation

Upgrade FortiClientEMS to a patched version beyond 7.4.6. If immediate patching is not feasible, restrict network access to the EMS management interface to trusted sources only.

Patch Commit

Weakness (CWE)

CWE-284 Improper Access Control

EPSS Score

90.75%
Probability of exploitation in next 30 days
99.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE