Executive brief
FortiSandbox is a security appliance used to identify advanced threats by executing suspicious files in a safe, isolated environment. A critical vulnerability allows an unauthenticated attacker to take full control of the system by sending a specially crafted web request. This could lead to the theft of sensitive data, disruption of security scanning operations, or use of the appliance as a foothold to attack other parts of the corporate network.
Technical details
An OS command injection vulnerability (CWE-78) exists in the FortiSandbox API due to improper neutralization of special elements in the 'jid' parameter. Specifically, the '/fortisandbox/job-detail/tracer-behavior' endpoint fails to sanitize input before passing it to a system shell. An unauthenticated remote attacker can exploit this by using shell metacharacters (such as the pipe symbol '|') within a GET request to execute arbitrary commands with root privileges. This vulnerability affects FortiSandbox versions 4.4.0 through 4.4.8 and has been observed in the wild. Users should upgrade to version 4.4.9 or later.
Affected products
- Fortinet FortiSandbox 4.4.0 through 4.4.8
- Fortinet FortiSandbox PaaS 21.3.4055 through 23.4.4374
Timeline
- 2025-11: other: Vulnerability discovered
- 2026-04-14: disclosed: Initial vendor advisory published
- 2026-04-14: patched: Fix released in version 4.4.9
- 2026-07-16: kev added: Added to CISA KEV catalog due to active exploitation