[CIVN-2026-0265] Remote Code Execution Vulnerability in Fortinet FortiSandbox Products

By Published On: May 25, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Remote Code Execution Vulnerability in Fortinet FortiSandbox Products


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Software Affected


FortiSandbox versions 5.0.0 through 5.0.1

FortiSandbox versions 4.4.0 through 4.4.8

FortiSandbox Cloud all versions of 23 and 24

FortiSandbox Cloud versions 5.0.2 through 5.0.5

FortiSandbox PaaS versions all version of 23.4, 23.3, 23.1, 22.2, 22.1, 21.4 and 21.3

FortiSandbox PaaS versions 5.0.0 through 5.0.1

FortiSandbox PaaS versions 4.4.5 through 4.4.8

Overview


A vulnerability has been reported in Fortinet FortiSandbox products, which could allow an unauthenticated attacker to execute unauthorized code or commands on the targeted system.


Target Audience:

All organizations and individuals using Fortinet FortiSandbox products.


Risk Assessment:

High risk of remote unauthorized code execution on affected systems.


Impact Assessment:

High risk of information disclosure, privilege misuse, and full system compromise.


Description


Fortinet FortiSandbox is an advanced threat detection solution that isolates and analyzes suspicious files and URLs in a secure sandbox environment to identify zero-day and targeted attacks.


The vulnerability exists in Fortinet FortiSandbox products due to improper authorization controls. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the targeted system.


Successful exploitation of this vulnerability could allow remote code execution on the affected system without authentication.


Solution


Apply appropriate updates as mentioned in the vendor advisory:

https://www.fortiguard.com/psirt/FG-IR-26-136



Vendor Information


Fortinet

https://www.fortiguard.com/psirt


References


Fortinet

https://www.fortiguard.com/psirt/FG-IR-26-136


CVE Name

CVE-2026-26083




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEEp2gIPkR1VyW4GqN5IVbAwLYg0LQFAmoUXeEACgkQIVbAwLYg

0LTokBAAk15ykEux3MxJWZTaUyCR44x3CZcgwZum8kD6Y5RwqEI2iCoLtUv1coej

sVc+QAckrqTNYDdxRZ+lmCbQUmxqxruYAQh2FGA4uLTbnxA7E3ZmSvuKSKasdRnR

p9quojC5Y752MYkT5iKRMZ5JaraFAmndEY0Qq43OK+PhE0oWHcZ/6JINC1Z0iqgc

jCkcFBxqymtmg+f6LM9gyzIKR6sYWlviEITeNJol5reNs+fwV5c1AY+4CpamNUtz

NzVQEAio4ZCdkb2RFfXxIHgTi8e8V7Na1+pH1WZMyWcTyz3KKNZaUUMhJ7wbWhDq

5xEudMlGttd0B4Eu7AmcpyeVCi2rkxYlV//fBfEEApqkY0dTaykQwxcZ5p1CIpAc

PHwrfVs47SpfeFTxqSJ+cgNsvt/iwDg7P7tAaSndT1VckPcdpbsAb7D0jE69Rkhz

i2LPlLY7CcbwNUQI/YMFC5j9oKPfYAJlRIOqWq3lNasji2nRKRWJePiSo58VBP97

ihWbgjRgKyD87/B/1LAq5SrFU5lgmFjxl2+tUkgwilJL8CuuOjs1COdkjkgWXH8X

3ttlWxD4FzdKfSo7LiwJPhV+QWzvqxWexR42dyy/a+04+8rx99DOx7/HvUNrc7uF

RU+L00JI/j4wh5blPtO6Z/BeBOTGwujViE70R8huf3quw2PMi/Q=

=KDoY

—–END PGP SIGNATURE—–

Share this article