Vulnerability Details CVE-2026-35616
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 10.0%
CVSS Severity
CVSS v3 Score 9.8
Proposed Action
Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
Ransomware Campaign
Unknown
Products affected by CVE-2026-35616
-
cpe:2.3:a:fortinet:forticlientems:7.4.5
-
cpe:2.3:a:fortinet:forticlientems:7.4.6