Description
A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2 all versions may allow attacker to information disclosure via <insert attack vector here>
Published: 2026-07-14
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an improper certificate validation error (CWE‑295) in Fortinet FortiClientEMS. Because the client does not properly verify certificates, sensitive information can be exposed if an attacker can trick the client into trusting a malicious certificate. The CVE provides no explicit attack vector; it is inferred that the weakness could be exploited remotely by manipulating traffic that triggers client‑certificate validation.

Affected Systems

The flaw affects Fortinet FortiClientEMS across multiple releases, including all 7.2.x versions, the 7.4.0 and 7.4.1 releases, and the 7.4.3 through 7.4.5 releases. These versions are listed as vulnerable in the Fortinet advisory and are included in the affected CPEs.

Risk and Exploitability

The CVSS score of 6.7 indicates a medium severity, suggesting that the breach could result in the disclosure of confidential data but does not grant direct control over the system. EPSS is less than 1%, implying that exploitation in the wild is considered rare but possible. As the vulnerability is not listed in the CISA KEV catalog, there are no confirmed widespread attacks. An attacker could potentially intercept or read confidential data that passes through the client by exploiting the weakened certificate validation, but no public exploit has been documented.

Generated by OpenCVE AI on July 31, 2026 at 10:11 UTC.

Remediation

Vendor Solution

Upgrade to upcoming FortiClientEMS version 8.0.0 or above Upgrade to FortiClientEMS version 7.4.6 or above


OpenCVE Recommended Actions

  • Upgrade FortiClientEMS to version 7.4.6 or later, or to 8.0.0 or above, to deploy the vendor’s fix for the certificate validation issue.
  • If an immediate upgrade is not feasible, contact Fortinet Support to obtain guidance on interim mitigation steps and to confirm whether any temporary configuration changes can reduce the risk.
  • Audit existing client‑certificate configurations and remove or replace any custom or untrusted certificates to ensure that only properly validated certificates are accepted by the client.

Generated by OpenCVE AI on July 31, 2026 at 10:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Improper Certificate Validation in FortiClientEMS Leading to Information Disclosure

Sun, 26 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Improper Certificate Validation in FortiClientEMS Leading to Information Disclosure

Fri, 24 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Improper Certificate Validation in FortiClientEMS Leading to Information Disclosure

Fri, 17 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Improper Certificate Validation in FortiClientEMS Leading to Information Disclosure

Thu, 16 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Improper Certificate Validation in FortiClientEMS Leading to Information Disclosure

Tue, 14 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2 all versions may allow attacker to information disclosure via <insert attack vector here>
First Time appeared Fortinet
Fortinet forticlientems
Weaknesses CWE-295
CPEs cpe:2.3:a:fortinet:forticlientems:7.2.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientems:7.2.10:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientems:7.2.12:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientems:7.2.13:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientems:7.2.14:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientems:7.2.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientems:7.2.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientems:7.2.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientems:7.2.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientems:7.2.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientems:7.2.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientems:7.2.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientems:7.2.8:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientems:7.2.9:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientems:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientems:7.4.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientems:7.4.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientems:7.4.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientems:7.4.5:*:*:*:*:*:*:*
Vendors & Products Fortinet
Fortinet forticlientems
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C'}


Subscriptions

Fortinet Forticlientems
cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published:

Updated: 2026-07-15T03:59:06.023Z

Reserved: 2026-07-07T15:21:26.614Z

Link: CVE-2026-59836

cve-icon Vulnrichment

Updated: 2026-07-14T16:03:00.069Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T10:15:06Z

Weaknesses
  • CWE-295

    Improper Certificate Validation