CVE-2026-35616 Details
Description
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
A vulnerability allowing improper access control has been identified in Fortinet FortiClient EMS versions 7.4.5 through 7.4.6. This vulnerability may enable an unauthenticated attacker to execute unauthorized code or commands by sending crafted requests.
Users are advised to upgrade to FortiClient EMS version 7.4.7 or above. For those currently using FortiClient EMS 7.4.5 or 7.4.6, a hotfix is available. Instructions for applying the hotfix can be found in the FortiClient EMS release notes for versions 7.4.5 and 7.4.6.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-35616 | CISA-ADP | US Government Resource |
| https://fortiguard.fortinet.com/psirt/FG-IR-26-099 | [email protected] | PatchVendor Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Fortinet FortiClient EMS Improper Access Control Vulnerability | Apr 6, 2026 | Apr 9, 2026 | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| fortinet forticlientems | 7.4.5 7.4.6 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 6, 2026 | Initial Analysis | [email protected] |
| Apr 6, 2026 | CVE Modified | CISA-ADP |
| Apr 4, 2026 | New CVE Received | [email protected] |