Executive brief
Fortinet FortiSandbox, a security tool used to identify and isolate advanced threats, contains a critical vulnerability in its programming interface. An attacker can exploit this flaw to bypass security checks and gain unauthorized administrative control over the system. This could allow an attacker to disrupt security operations or access sensitive data processed by the sandbox environment.
Technical details
A path traversal vulnerability (CWE-24) exists in the JRPC API component of Fortinet FortiSandbox. The flaw is caused by improper validation of '../filedir' sequences in HTTP requests, which allows an unauthenticated remote attacker to bypass authentication mechanisms. Successful exploitation enables the attacker to achieve full privilege escalation on the device. The vulnerability affects FortiSandbox versions 5.0.0-5.0.5 and 4.4.0-4.4.8, as well as specific versions of FortiSandbox Cloud. Users are advised to upgrade to versions 5.0.6 or 4.4.9 respectively.
Affected products
- Fortinet FortiSandbox 5.0.0 through 5.0.5, 4.4.0 through 4.4.8
- Fortinet FortiSandbox Cloud 23.4, 24.1, 5.0.4 through 5.0.5
Timeline
- 2026-04-14: disclosed: Initial publication of the advisory by Fortinet.
- 2026-04-14: advisory: NVD entry created.
- 2026-06-18: other: Last modified date for the CVE record.