CVE-2026-35616 PUBLISHED

Assigner: fortinet
Reserved: 03.04.2026 Published: 04.04.2026 Updated: 04.04.2026

A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
CVSS Score: 9.1

Product Status

Vendor Fortinet
Product FortiClientEMS
Versions Default: unaffected
  • affected from 7.4.5 to 7.4.6 (incl.)

Solutions

Upgrade to upcoming FortiClientEMS version 7.4.7 or above Upgrade to upcoming FortiClientEMS version 7.2.11 or above

References

Problem Types

  • Escalation of privilege CWE