CVE-2026-35616

A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

Severity
Critical 9.1
CVSS 3.1
Exploited
Yes — in CISA KEV
Added Apr 6, 2026
EPSS
0.889
99.8th percentile
Discovered by
Not disclosed
Published
Apr 4, 2026
Assigned by fortinet

Description

A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

Weakness: CWE-284

Affected products

Vendor Product Category Matched by
Fortinet FortiClient Endpoint / EDR cna-assigner
Vendor-reported affected versions (1)
  • Fortinet · FortiClientEMS

Vendor remediation

Upgrade to upcoming FortiClientEMS version 8.0.0 or above Upgrade to FortiClientEMS version 7.4.7 or above