Summary
FortiClient EMS 7.4.5–7.4.6 contain an improper access control flaw in the API authentication/authorization layer that lets unauthenticated attackers send crafted HTTPS requests to EMS administrative functions. Successful exploitation can bypass access checks and trigger unauthorized commands or code execution on the EMS server. Fortinet says the issue is being exploited in the wild and provides a hotfix plus a fixed 7.4.7 release.
Why Fix Soon?
6/6Exploitation Details
Execute arbitrary code or commands on the FortiClient EMS server, potentially leading to full compromise of the EMS and downstream managed endpoints.
RCE (Remote Code Execution)Affected Software
| Product | Affected Versions |
|---|---|
| FortiClient EMS | 7.4.5 through 7.4.6 |
Centralized endpoint management server for FortiClient agents, used to deploy configurations, policies, telemetry, and software updates across enterprise endpoints.
Affected ComponentFortiClient EMS web/API authentication and authorization layer handling administrative requests.
FortiClient EMS web/API authentication and authorization layer handling administrative requests.
Restrict EMS web/API access to trusted IP ranges or VPN users and block public exposure of TCP/443; Fortinet documentation notes EMS web access uses 443 and recommends blocking other ports or service requests to the EMS IP/FQDN.
Restrict EMS web/API access to trusted IP ranges or VPN users and block public exposure of TCP/443; Fortinet documentation notes EMS web access uses 443 and recommends blocking other ports or service requests to the EMS IP/FQDN.
Apply Fortinet's EMS hotfix package on FortiClient EMS 7.4.5 or 7.4.6 using the vendor's hotfix installation instructions.
Apply Fortinet's EMS hotfix package on FortiClient EMS 7.4.5 or 7.4.6 using the vendor's hotfix installation instructions.
Upgrade FortiClient EMS to 7.4.7 or later; Fortinet says the 7.4.5 and 7.4.6 hotfixes also fully prevent the issue.
Upgrade FortiClient EMS to 7.4.7 or later; Fortinet says the 7.4.5 and 7.4.6 hotfixes also fully prevent the issue.
Probability of exploitation in the next 30 days
Worse than 10% of all CVEs
No known threat actors
No detection rules available
NVD Data
Description Summary
CVSS Base Score
CVSS Vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Sources
| Source | Article |
|---|---|
| fortiguard.fortinet.com | FG-IR-26-099 API authentication and authorization bypass |
| docs.fortinet.com | FortiClient EMS Introduction |
| docs.fortinet.com | Required services and ports |
| tenable.com | CVE-2026-35616 |
Priority History
Initial analysis