/Vulnerability Library

FortiClient EMS - Authentication Bypass

CVE-2026-35616
Verified

Description

Detects whether Fortinet hotfix FG-IR-26-099 for CVE-2026-35616 is missing by comparing behavioral responses from a certificate-authenticated endpoint. The template sends X-SSL-CLIENT-VERIFY: SUCCESS without certificate material and checks whether this spoofed header changes server behavior.

Severity

High

Exploit Probability

9%

Affected Product

forticlient_ems

Published Date

April 9, 2026

Template Author

ritikchaddha

CVE-2026-35616.yaml
7.5Severity

CVSS Metrics

CVE ID:
cve-2026-35616
CWE ID:
cwe-284

References

https://bishopfox.com/blog/api-authentication-bypass-in-forticlient-ems-7-4-5-7-4-6-cve-2026-35616https://nvd.nist.gov/vuln/detail/CVE-2026-35616

Remediation Steps

Apply Fortinet hotfix FG-IR-26-099 or upgrade to FortiClient EMS 7.4.7+.