Junglewise Threat Intelligence

CVE-2026-39808: Fortinet FortiSandbox OS command injection in API endpoint

CVE-2026-39808 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2026-04-14

Technologies: Fortinet FortiSandbox, Fortinet FortiSandbox PaaS. Vendors: Fortinet.

Executive brief

FortiSandbox is a security appliance used to identify advanced threats by executing suspicious files in a safe, isolated environment. A critical vulnerability allows an unauthenticated attacker to take full control of the system by sending a specially crafted web request. This could lead to the theft of sensitive data, disruption of security scanning operations, or use of the appliance as a foothold to attack other parts of the corporate network.

Technical details

An OS command injection vulnerability (CWE-78) exists in the FortiSandbox API due to improper neutralization of special elements in the 'jid' parameter. Specifically, the '/fortisandbox/job-detail/tracer-behavior' endpoint fails to sanitize input before passing it to a system shell. An unauthenticated remote attacker can exploit this by using shell metacharacters (such as the pipe symbol '|') within a GET request to execute arbitrary commands with root privileges. This vulnerability affects FortiSandbox versions 4.4.0 through 4.4.8 and has been observed in the wild. Users should upgrade to version 4.4.9 or later.

Affected products

  • Fortinet FortiSandbox 4.4.0 through 4.4.8
  • Fortinet FortiSandbox PaaS 21.3.4055 through 23.4.4374

Timeline

  • 2025-11: other: Vulnerability discovered
  • 2026-04-14: disclosed: Initial vendor advisory published
  • 2026-04-14: patched: Fix released in version 4.4.9
  • 2026-07-16: kev added: Added to CISA KEV catalog due to active exploitation

References

Related threats