CVE-2026-39810
MEDIUMFortiClientEMS 7.4.0-7.4.5 - Information Disclosure via Hard-coded Cryptographic Key
Title source: llmDescription
A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5 may allow attacker to information disclosure via decrypting database dump.
References (1)
Core 1
Core References
Scores
CVSS v3
6.0
EPSS
0.0010
EPSS Percentile
1.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-321
Status
published
Products (3)
Fortinet/FortiClientEMS
7.4.0 - 7.4.1
fortinet/forticlientems
7.4.0 - 7.4.6
Fortinet/FortiClientEMS
7.4.3 - 7.4.5
Published
Apr 14, 2026
Tracked Since
Apr 14, 2026