CVE-2023-48786: Fortinet FortiClient EMS

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A server-side request forgery vulnerability [CWE-918] in Fortinet FortiClientEMS version 7.4.0 through 7.4.2 and before 7.2.6 may allow an authenticated attacker to perform internal requests via crafted HTTP or HTTPS requests.

Affected products

  • Fortinet FortiClient EMS: from 6.4.0, up to and including 6.4.9; from 7.0.0, up to and including 7.0.13; from 7.2.0, before 7.2.7 (fixed in 7.2.7); from 7.4.0, before 7.4.3 (fixed in 7.4.3)

Published 2025-06-10. Last modified 2026-06-17.