Hardcoded symmetric encryption key for Postgresql

Summary

A use of hard-coded cryptographic key vulnerability [CWE 321] in FortiClientEMS may allow an attacker in possession of an encrypted dump of the database to decrypt it.

Version Affected Solution
FortiClientEMS 7.4 7.4.0 through 7.4.5 Upgrade to 7.4.6 or above
FortiClientEMS 7.2 Not affected Not Applicable
FortiClientEMS 7.0 Not affected Not Applicable

Acknowledgement

Internally discovered and reported by David Maciejak of Fortinet Product Security team.

Timeline

2026-04-14: Initial publication