Missing authorization in FortiClientEMS - CVE-2026-35616
Published: April 4, 2026
FortiClientEMS
Detailed vulnerability description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to missing authorization checks. A remote non-authenticated attacker can send a specially crafted HTTP request to certain API endpoint and execute arbitrary commands on the system.
Note, the vulnerability is being actively exploited in the wild.
How to mitigate CVE-2026-35616
It is recommended to upgrade FortiClientEMS toversion 7.4.7 when it becomes available.
As a temporary solution it is recommended to apply a hotfix following the instructions below:
https://docs.fortinet.com/document/forticlient/7.4.5/ems-release-notes/832484 - for FortiClientEMS 7.4.5
https://docs.fortinet.com/document/forticlient/7.4.6/ems-release-notes/832484 - for FortiClientEMS 7.4.6