CVE-2026-39810 PUBLISHED

Assigner: fortinet
Reserved: 07.04.2026 Published: 14.04.2026 Updated: 14.04.2026

A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5 may allow attacker to information disclosure via <insert attack vector here>

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C
CVSS Score: 5.2

Product Status

Vendor Fortinet
Product FortiClientEMS
Versions Default: unaffected
  • affected from 7.4.3 to 7.4.5 (incl.)
  • affected from 7.4.0 to 7.4.1 (incl.)

Solutions

Upgrade to FortiClientEMS version 7.4.6 or above

References

Problem Types

  • Information disclosure CWE