[CIVN-2026-0197] Multiple Vulnerabilities in Fortinet FortiSandbox

By Published On: April 21, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in Fortinet FortiSandbox


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Software Affected


FortiSandbox versions 4.4.0 through 4.4.8

FortiSandbox versions 5.0.0 through 5.0.5

Overview


Multiple vulnerabilities have been reported in Fortinet FortiSandbox, which could allow an attacker to bypass authentication controls, escalate privileges and execute arbitrary code on the targeted system.


Target Audience:

All organizations and individuals using Fortinet FortiSandbox.


Risk Assessment:

High risk of complete system compromise.


Impact Assessment:

Execution of unauthorized code or commands, bypass authentication mechanisms, escalation of privilege and disclosure of sensitive information.


Description


Fortinet FortiSandbox is an advanced threat detection solution that isolates and analyzes suspicious files and URLs in a secure sandbox environment to identify zero-day and targeted attacks.


These vulnerabilities exist in FortiSandbox due to OS command injection and path traversal issues. An attacker can exploit these vulnerabilities by sending specially crafted HTTP requests.


Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication controls, escalate privileges and execute arbitrary code on the targeted system.


Solution


Apply appropriate updates as mentioned in the vendor advisory:

https://www.fortiguard.com/psirt/FG-IR-26-100


https://www.fortiguard.com/psirt/FG-IR-26-112



Vendor Information


Fortinet

https://www.fortiguard.com/psirt


References


 

https://www.fortiguard.com/psirt/FG-IR-26-100

https://www.fortiguard.com/psirt/FG-IR-26-112


CVE Name

CVE-2026-39808

CVE-2026-39813




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmnnkkUACgkQ3jCgcSdc

ys9lhw/9Hi4v+l5WopnsM/3iJj5bGpU+EG8vOL/suB56Lt9T2821v1SIfkpOU1ey

AhHPNJEj/s25vwUEf1aA7qUQYs8GR299OI20HN0EsKvbA4lbtT/0ExBYxoNSXV2b

pEOfDCEmvwiSL4BTLoEm5cbFantfXxiQvQV4OSKxYtKftF4na6CCPlxaGP7ExYEJ

hFZi/X8r9yPiWD4lZH+/rYMLgKL8XSgGe4bVUVCOElPIp2JO7hu8he+P1kXBGShQ

4vgHYC1CwJzrlCTRSUuHkxqpGbYTiAPLZc9lMbd+4gk542ED8e7OgvpIDSO474eG

OPD9902fDhzK/jPOI2IuwDgQBYaYOkSZkmoBdQ1ngC5HbsQgkeN1sMWssVjyWian

sRQN5v1LAJX3697kDDGUo5iz2iR7Jhua0nrLyM3sagDpIFv1DzZ2BCKKSD88afGQ

U/wPrsI5OD/Gysi4GKOimtMVAYBjE8m7fXr5ttn4sXNhALO7k+PkKYDRl2vlmKDj

uV7uUc8IfC7pio6dCtveaP73/xWMWEmTv572BMDxKd/U3ij5RMcGVEKgaaWZCDfH

1pIhhKmwsCfqRw9NxAlwAKZMIPG7YBf4cnQLjN3KjPqnQuVIebBjfxiYudVmXqmm

osCrcpg140NcLwWyqLnBosaJeb2+pABjFW0FjbLRibXmBd+VziA=

=ptsM

—–END PGP SIGNATURE—–

Share this article