Executive brief
Fortinet FortiSandbox Cloud and PaaS are security solutions used to analyze suspicious files in a safe, isolated environment to detect malware. A vulnerability in the management interface could allow a highly privileged administrator to execute unauthorized system commands. While this requires existing administrative access, an exploit could allow an attacker to bypass intended security restrictions and gain deeper control over the sandbox infrastructure.
Technical details
An OS command injection vulnerability (CWE-78) exists in the 'vmimages update' feature of the FortiSandbox Cloud and PaaS Web UI. The flaw is caused by improper neutralization of special elements within HTTP requests processed by the management interface. A remote attacker with super-admin privileges and CLI access can exploit this by sending specially crafted HTTP requests to execute arbitrary code or commands on the underlying operating system. The vulnerability is fixed in version 5.0.5 and above. Although the vendor's internal advisory lists a CVSS of 6.7, the NVD record reflects a CVSS 3.1 score of 7.2.
Affected products
- Fortinet FortiSandbox Cloud 5.0.4
- Fortinet FortiSandbox PaaS 5.0.4
Timeline
- 2026-03-10: disclosed: Initial publication by Fortinet
- 2026-03-10: advisory: NVD entry created
- 2026-03-26: other: Advisory updated to include FortiSandbox PaaS