
[CIVN-2026-0197] Multiple Vulnerabilities in Fortinet FortiSandbox
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Fortinet FortiSandbox
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
FortiSandbox versions 4.4.0 through 4.4.8
FortiSandbox versions 5.0.0 through 5.0.5
Overview
Multiple vulnerabilities have been reported in Fortinet FortiSandbox, which could allow an attacker to bypass authentication controls, escalate privileges and execute arbitrary code on the targeted system.
Target Audience:
All organizations and individuals using Fortinet FortiSandbox.
Risk Assessment:
High risk of complete system compromise.
Impact Assessment:
Execution of unauthorized code or commands, bypass authentication mechanisms, escalation of privilege and disclosure of sensitive information.
Description
Fortinet FortiSandbox is an advanced threat detection solution that isolates and analyzes suspicious files and URLs in a secure sandbox environment to identify zero-day and targeted attacks.
These vulnerabilities exist in FortiSandbox due to OS command injection and path traversal issues. An attacker can exploit these vulnerabilities by sending specially crafted HTTP requests.
Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication controls, escalate privileges and execute arbitrary code on the targeted system.
Solution
Apply appropriate updates as mentioned in the vendor advisory:
https://www.fortiguard.com/psirt/FG-IR-26-100
https://www.fortiguard.com/psirt/FG-IR-26-112
Vendor Information
Fortinet
https://www.fortiguard.com/psirt
References
https://www.fortiguard.com/psirt/FG-IR-26-100
https://www.fortiguard.com/psirt/FG-IR-26-112
CVE Name
CVE-2026-39808
CVE-2026-39813
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmnnkkUACgkQ3jCgcSdc
ys9lhw/9Hi4v+l5WopnsM/3iJj5bGpU+EG8vOL/suB56Lt9T2821v1SIfkpOU1ey
AhHPNJEj/s25vwUEf1aA7qUQYs8GR299OI20HN0EsKvbA4lbtT/0ExBYxoNSXV2b
pEOfDCEmvwiSL4BTLoEm5cbFantfXxiQvQV4OSKxYtKftF4na6CCPlxaGP7ExYEJ
hFZi/X8r9yPiWD4lZH+/rYMLgKL8XSgGe4bVUVCOElPIp2JO7hu8he+P1kXBGShQ
4vgHYC1CwJzrlCTRSUuHkxqpGbYTiAPLZc9lMbd+4gk542ED8e7OgvpIDSO474eG
OPD9902fDhzK/jPOI2IuwDgQBYaYOkSZkmoBdQ1ngC5HbsQgkeN1sMWssVjyWian
sRQN5v1LAJX3697kDDGUo5iz2iR7Jhua0nrLyM3sagDpIFv1DzZ2BCKKSD88afGQ
U/wPrsI5OD/Gysi4GKOimtMVAYBjE8m7fXr5ttn4sXNhALO7k+PkKYDRl2vlmKDj
uV7uUc8IfC7pio6dCtveaP73/xWMWEmTv572BMDxKd/U3ij5RMcGVEKgaaWZCDfH
1pIhhKmwsCfqRw9NxAlwAKZMIPG7YBf4cnQLjN3KjPqnQuVIebBjfxiYudVmXqmm
osCrcpg140NcLwWyqLnBosaJeb2+pABjFW0FjbLRibXmBd+VziA=
=ptsM
—–END PGP SIGNATURE—–


