CVE-2026-39810
A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5 may allow attacker to information disclosure via decrypting database dump.
Severity
Medium 5.2
CVSS 3.1
Exploited
Not listed
EPSS
0.001
1.0th percentile
Discovered by
Not disclosed
Published
Apr 14, 2026
Assigned by fortinet
Description
A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5 may allow attacker to information disclosure via decrypting database dump.
Weakness: CWE-321
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiClient | Endpoint / EDR | cna-assigner |
Vendor-reported affected versions (1)
- Fortinet · FortiClientEMS
Vendor remediation
Upgrade to FortiClientEMS version 7.4.6 or above