Executive brief
FortiClientEMS is a management solution used to deploy and monitor security software across corporate devices. A security flaw in how the system verifies digital certificates could allow an attacker to impersonate an Active Directory (AD) Connector. If exploited, this could lead to the unauthorized disclosure of sensitive information or the compromise of communication between the management server and the directory service.
Technical details
An improper certificate validation vulnerability (CWE-295) exists in the AD Connector communication component of Fortinet FortiClientEMS. The flaw allows a remote, unauthenticated attacker to impersonate a legitimate AD Connector by utilizing a valid API key while bypassing standard certificate verification checks. This attack requires a high level of complexity, typically involving a man-in-the-middle position or specific network conditions to intercept and redirect traffic. Successful exploitation can result in unauthorized information disclosure or the interception of sensitive directory data. Users are advised to upgrade to FortiClientEMS version 7.4.6 or later.
Affected products
- Fortinet FortiClientEMS 7.4.0 through 7.4.1, 7.4.3 through 7.4.5, 7.2 all versions
Timeline
- 2026-07-14: disclosed: Initial publication of FG-IR-26-147
- 2026-07-14: advisory: NVD publication date