PT-2026-30288 · Fortinet · Forticlientems

Published

2026-04-04

·

Updated

2026-04-04

·

CVE-2026-35616

CVSS v3.1

9.8

Critical

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2026-35616

Affected Products

Forticlientems