Executive brief
FortiSandbox is a security solution used to identify and analyze advanced threats by executing suspicious files in a safe, isolated environment. A critical vulnerability has been identified that allows an unauthorized person to take control of the system by sending specially crafted web requests. If exploited, an attacker could disrupt security operations, access sensitive analysis data, or use the compromised system as a foothold to attack other parts of the corporate network.
Technical details
An OS command injection vulnerability (CWE-78) exists in Fortinet FortiSandbox due to the improper neutralization of special elements in HTTP requests. The flaw resides in the handling of specific HTTP inputs, allowing a remote, unauthenticated attacker to inject and execute arbitrary operating system commands. The attack vector is network-based with low complexity and requires no user interaction or prior authentication. Successful exploitation results in a full compromise of the affected appliance or cloud instance (Total Impact). The vulnerability affects FortiSandbox versions 5.0.0-5.0.5, 4.4.0-4.4.8, and all 4.2 versions, as well as specific Cloud and PaaS versions. Users are advised to refer to Fortinet advisory FG-IR-26-141 for patching information.
Affected products
- Fortinet FortiSandbox 5.0.0 through 5.0.5, 4.4.0 through 4.4.8, 4.2 all versions
- Fortinet FortiSandbox Cloud 5.0.4 through 5.0.5
- Fortinet FortiSandbox PaaS 5.0.4 through 5.0.5
Timeline
- 2026-06-09: disclosed: NVD Published Date
- 2026-07-16: advisory: Date provided in advisory text