CVE-2026-44278
FortiClient vulnerability analysis and mitigation

Overview

CVE-2026-44278 is a use of hard-coded cryptographic key vulnerability (CWE-321) in Fortinet FortiClientWindows that may allow an authenticated local attacker to decrypt a currently logged-in user's VPN saved password via an unprotected DLL function. It affects FortiClientWindows versions 7.4.0 through 7.4.2 and all versions of FortiClientWindows 7.2. The vulnerability was disclosed on May 12, 2026, by Fortinet's PSIRT under advisory FG-IR-26-129. The CNA-assigned CVSS v3.1 base score is 2.3 (Low), while NVD's independent assessment rates it 5.5 (Medium) (FortiGuard PSIRT, Github Advisory).

Technical details

The root cause is the use of a hard-coded cryptographic key (CWE-321) within FortiClientWindows, specifically exposed through an unprotected DLL function. An authenticated local attacker with high privileges can call this DLL function to decrypt the VPN password of a currently logged-in user, bypassing the intended cryptographic protection. The attack vector is local, requires low attack complexity, and demands high privileges but no user interaction. The vulnerability was discovered externally and reported by Alex Ghiotto of HackerHood Research Group under responsible disclosure (FortiGuard PSIRT).

Impact

Successful exploitation results in information disclosure — specifically, the exposure of a currently logged-in user's VPN saved password. There is no impact on integrity or availability. While the scope is limited to the local system and requires elevated privileges, disclosure of VPN credentials could potentially enable lateral movement or unauthorized remote access to corporate networks if the credentials are reused or shared (FortiGuard PSIRT, Github Advisory).

Mitigation and workarounds

Fortinet recommends upgrading FortiClientWindows 7.4.x to version 7.4.3 or above. Users on the 7.2.x branch should migrate to a fixed release, as all 7.2 versions are affected with no in-branch fix available. As an interim measure, organizations should restrict local access and high-privilege accounts to authorized users only, and audit access logs for unauthorized access attempts (FortiGuard PSIRT).

Community reactions

The vulnerability received limited community attention. A Reddit thread in the r/fortinet community raised questions about whether the vulnerability would be remediated in the free version of FortiClient. Coverage was largely limited to automated CVE tracking and security news aggregators. No significant researcher commentary or major media coverage was identified beyond routine advisory republication (Reddit).

Additional resources


SourceThis report was generated using AI

Related FortiClient vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-24018HIGH7.8
  • FortiClient logoFortiClient
  • cpe:2.3:a:fortinet:forticlient
NoYesMar 10, 2026
CVE-2025-47761HIGH7.8
  • FortiClient logoFortiClient
  • cpe:2.3:a:fortinet:forticlient
NoYesNov 18, 2025
CVE-2025-62676HIGH7.1
  • FortiClient logoFortiClient
  • cpe:2.3:a:fortinet:forticlient
NoYesFeb 10, 2026
CVE-2026-44278MEDIUM5.5
  • FortiClient logoFortiClient
  • cpe:2.3:a:fortinet:forticlient
NoYesMay 12, 2026
CVE-2025-54660MEDIUM5.5
  • FortiClient logoFortiClient
  • cpe:2.3:a:fortinet:forticlient
NoYesNov 18, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management