Junglewise Threat Intelligence

CVE-2026-26083: Fortinet FortiSandbox missing authorization in Web UI

CVE-2026-26083 · Severity: critical · CVSS 9.8 · Published 2026-05-12

Technologies: Fortinet FortiSandbox, Fortinet Fortisandbox Cloud, Fortinet FortiSandbox PaaS. Vendors: Fortinet.

Executive brief

Fortinet FortiSandbox is a security solution used to identify and isolate advanced threats by analyzing suspicious files in a safe environment. A critical security flaw in its web management interface allows an unauthenticated attacker to remotely execute unauthorized commands. This could lead to a complete takeover of the sandbox system, potentially allowing attackers to bypass security inspections or gain a foothold in the corporate network.

Technical details

A missing authorization vulnerability (CWE-862) exists in the Web UI component of Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS. The flaw allows a remote, unauthenticated attacker to send crafted HTTP requests to the management interface to execute unauthorized code or system commands. The vulnerability stems from incorrect global authorization checks within the GUI. Successful exploitation grants the attacker full control over the affected appliance or cloud instance. Fortinet has released updates (e.g., 5.0.2, 4.4.9, 5.0.6) to address the issue.

Affected products

  • Fortinet FortiSandbox 5.0.0 through 5.0.1, 4.4.0 through 4.4.8, 4.2.1 through 4.2.8
  • Fortinet FortiSandbox Cloud 5.0.2 through 5.0.5, 23.x, 24.x
  • Fortinet FortiSandbox PaaS 21.3 through 23.4, 5.0.0 through 5.0.1, 4.4.5 through 4.4.8

Timeline

  • 2026-05-12: disclosed: Initial publication by Fortinet
  • 2026-05-12: advisory: FortiGuard Labs advisory FG-IR-26-136 published

References

Related threats