Executive brief
Fortinet FortiSandbox is a malware analysis and threat detection platform used to protect organizations against advanced threats. An improper access control flaw in the web interface allows unauthenticated attackers to access sensitive information by sending crafted HTTP requests, potentially exposing confidential data without requiring credentials or authentication.
Technical details
This is an improper access control vulnerability (CWE-284) in the FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS web UI that allows unauthenticated attackers to bypass authentication controls. The vulnerability is triggered through crafted HTTP requests that can manipulate NAT rules and gain unauthorized access to sensitive information. The attack requires no authentication and is network-reachable via the web interface. Fortinet has released patches: FortiSandbox 5.0.6 and above, FortiSandbox 4.4.9 and above, and corresponding cloud/PaaS versions (5.0.6 and above). No known active exploitation has been reported as of the advisory date.
Affected products
- Fortinet FortiSandbox 5.0.0 through 5.0.5, 4.4.0 through 4.4.8
- Fortinet FortiSandbox Cloud 5.0.4 through 5.0.5
- Fortinet FortiSandbox PaaS 5.0.4 through 5.0.5
Timeline
- 2026-09-08: disclosed
- 2026-09-08: patched: FortiSandbox 5.0.6+, 4.4.9+; Cloud/PaaS 5.0.6+