CVE-2026-35616
Fortinet FortiClient EMS Improper Access Control Vulnerability
- Published
- Apr 4, 2026
- Updated
- Jul 8, 2026
- Assigning CNA
- fortinet
- Evidence observed
- Apr 6, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.8%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
Sources
7- CVE-2026-35616Detection
CVE-2026-35616
Fortinet FortiClientEMS improper access control
- CVE-2026-35616-checkScanner
Non-destructive scanner for CVE-2026-35616, a pre-authentication API bypass in FortiClient EMS. Detects vulnerability by comparing HTTP responses with and without spoofed SSL headers, using only Python standard library.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.