Junglewise Threat Intelligence

CVE-2026-25836: Fortinet FortiSandbox Cloud OS command injection in Web UI

CVE-2026-25836 · Severity: high · CVSS 7.2 · Published 2026-03-10

Technologies: Fortinet Fortisandbox Cloud, Fortinet FortiSandbox PaaS. Vendors: Fortinet.

Executive brief

Fortinet FortiSandbox Cloud and PaaS are security solutions used to analyze suspicious files in a safe, isolated environment to detect malware. A vulnerability in the management interface could allow a highly privileged administrator to execute unauthorized system commands. While this requires existing administrative access, an exploit could allow an attacker to bypass intended security restrictions and gain deeper control over the sandbox infrastructure.

Technical details

An OS command injection vulnerability (CWE-78) exists in the 'vmimages update' feature of the FortiSandbox Cloud and PaaS Web UI. The flaw is caused by improper neutralization of special elements within HTTP requests processed by the management interface. A remote attacker with super-admin privileges and CLI access can exploit this by sending specially crafted HTTP requests to execute arbitrary code or commands on the underlying operating system. The vulnerability is fixed in version 5.0.5 and above. Although the vendor's internal advisory lists a CVSS of 6.7, the NVD record reflects a CVSS 3.1 score of 7.2.

Affected products

  • Fortinet FortiSandbox Cloud 5.0.4
  • Fortinet FortiSandbox PaaS 5.0.4

Timeline

  • 2026-03-10: disclosed: Initial publication by Fortinet
  • 2026-03-10: advisory: NVD entry created
  • 2026-03-26: other: Advisory updated to include FortiSandbox PaaS

References

Related threats