CVE-2026-35616: FortiClient EMS Reverse-Proxy Header Spoofing Auth Bypass
A deep dive into CVE-2026-35616 — the FortiClient EMS authentication bypass. The Django CertChainAuth middleware blindly trusts the X-SSL-CLIENT-VERIFY HTTP header, so any unauthenticated client can spoof a verified-client-certificate state and walk straight past the auth gate. Full root-cause analysis, a 401→500 detection oracle, an unauthenticated 225 KB data-disclosure endpoint, a read-only enumeration PoC, and remediation.
2026-05-13