A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
Advisories
No advisories yet.
Fixes
Solution
Upgrade to upcoming FortiClientEMS version 7.4.7 or above Upgrade to upcoming FortiClientEMS version 7.2.11 or above
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-26-099 |
|
History
Sat, 04 Apr 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. | |
| First Time appeared |
Fortinet
Fortinet forticlientems |
|
| Weaknesses | CWE-284 | |
| CPEs | cpe:2.3:a:fortinet:forticlientems:7.4.5:*:*:*:*:*:*:* cpe:2.3:a:fortinet:forticlientems:7.4.6:*:*:*:*:*:*:* |
|
| Vendors & Products |
Fortinet
Fortinet forticlientems |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2026-04-04T00:39:55.593Z
Reserved: 2026-04-03T23:49:34.986Z
Link: CVE-2026-35616
No data.
Status : Received
Published: 2026-04-04T01:16:39.720
Modified: 2026-04-04T01:16:39.720
Link: CVE-2026-35616
No data.
OpenCVE Enrichment
No data.
Weaknesses