Junglewise Threat Intelligence

CVE-2026-59835: Fortinet FortiSandbox unauthenticated VNC access in scanning VMs

CVE-2026-59835 · Severity: high · CVSS 8.6 · Published 2026-07-14

Technologies: Fortinet FortiSandbox. Vendors: Fortinet.

Executive brief

A security vulnerability in Fortinet FortiSandbox could allow an unauthorized person to remotely view the screens of virtual machines used for malware analysis. FortiSandbox is a security tool that inspects suspicious files in isolated environments; this flaw could allow an attacker to observe sensitive scanning activities or potentially interact with the analysis environment. Organizations using affected versions should upgrade to the latest firmware to secure these interfaces.

Technical details

An 'Exposure of Resource to Wrong Sphere' vulnerability (CWE-668) exists in Fortinet FortiSandbox versions 5.0.0-5.0.2 and 4.4.3-4.4.8. The flaw allows unauthenticated VNC access to be exposed on all network interfaces. A remote attacker can exploit this by sending network requests to the VNC server of the virtual machines (VMs) currently performing file scanning. This could lead to unauthorized information disclosure or interaction with the sandboxed environment. The issue is resolved in FortiSandbox versions 5.0.3 and 4.4.9.

Affected products

  • Fortinet FortiSandbox 5.0.0 through 5.0.2, 4.4.3 through 4.4.8

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats