Fortinet FortiClient EMS Improper Access Control Vulnerability

Release Date: 6th April 2026

Impact : HIGH / CRITICAL

TLP Rating: Clear

Communication and Digital Transformation (DCDT through CERT Vanuatu (CERTVU), provides the following advisory

This alert is relevant to Organizations and System/Network administrators that utilize the above products. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-35616 is a critical remote code execution (RCE) vulnerability (CVSS 9.8) affecting Fortinet FortiClient Endpoint Management Server (EMS). The flaw is caused by improper access control (CWE-284) in the application’s API.

Due to insufficient authentication enforcement, the system fails to properly restrict access to sensitive API endpoints. This allows attackers to send crafted requests that bypass authentication and execute unauthorized commands.

 

References

  1. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  2. https://www.cve.org/CVERecord?id=CVE-2026-35616
  3. https://fortiguard.fortinet.com/psirt/FG-IR-26-099