
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-44278 is a use of hard-coded cryptographic key vulnerability (CWE-321) in Fortinet FortiClientWindows that may allow an authenticated local attacker to decrypt a currently logged-in user's VPN saved password via an unprotected DLL function. It affects FortiClientWindows versions 7.4.0 through 7.4.2 and all versions of FortiClientWindows 7.2. The vulnerability was disclosed on May 12, 2026, by Fortinet's PSIRT under advisory FG-IR-26-129. The CNA-assigned CVSS v3.1 base score is 2.3 (Low), while NVD's independent assessment rates it 5.5 (Medium) (FortiGuard PSIRT, Github Advisory).
The root cause is the use of a hard-coded cryptographic key (CWE-321) within FortiClientWindows, specifically exposed through an unprotected DLL function. An authenticated local attacker with high privileges can call this DLL function to decrypt the VPN password of a currently logged-in user, bypassing the intended cryptographic protection. The attack vector is local, requires low attack complexity, and demands high privileges but no user interaction. The vulnerability was discovered externally and reported by Alex Ghiotto of HackerHood Research Group under responsible disclosure (FortiGuard PSIRT).
Successful exploitation results in information disclosure — specifically, the exposure of a currently logged-in user's VPN saved password. There is no impact on integrity or availability. While the scope is limited to the local system and requires elevated privileges, disclosure of VPN credentials could potentially enable lateral movement or unauthorized remote access to corporate networks if the credentials are reused or shared (FortiGuard PSIRT, Github Advisory).
Fortinet recommends upgrading FortiClientWindows 7.4.x to version 7.4.3 or above. Users on the 7.2.x branch should migrate to a fixed release, as all 7.2 versions are affected with no in-branch fix available. As an interim measure, organizations should restrict local access and high-privilege accounts to authorized users only, and audit access logs for unauthorized access attempts (FortiGuard PSIRT).
The vulnerability received limited community attention. A Reddit thread in the r/fortinet community raised questions about whether the vulnerability would be remediated in the free version of FortiClient. Coverage was largely limited to automated CVE tracking and security news aggregators. No significant researcher commentary or major media coverage was identified beyond routine advisory republication (Reddit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."