Junglewise Threat Intelligence

CVE-2026-44278: Fortinet FortiClientWindows hard-coded cryptographic key in GUI

CVE-2026-44278 · Severity: low · CVSS 2.3 · Published 2026-05-12

Vendors: Fortinet.

Executive brief

FortiClient is an endpoint security application used to provide secure VPN access to corporate networks. A security flaw in the Windows version of this software could allow a local attacker with high privileges to recover saved VPN passwords. This could lead to unauthorized access to the corporate network if the attacker manages to compromise a user's workstation.

Technical details

A use of a hard-coded cryptographic key (CWE-321) and missing authorization (CWE-862) exists in the FortiClient Windows GUI component. The vulnerability stems from an unprotected DLL function that utilizes a static key for encrypting saved VPN credentials. An authenticated local attacker with high privileges (PR:H) can exploit this to decrypt the VPN password of the currently logged-in user. The issue affects FortiClientWindows versions 7.4.0 through 7.4.2 and all versions of 7.2. Users are advised to upgrade to version 7.4.3 or later.

Affected products

  • Fortinet FortiClientWindows 7.4.0 through 7.4.2, 7.2 all versions

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats