Junglewise Threat Intelligence

CVE-2026-84387: Fortinet FortiSandbox command injection in HTTP requests

CVE-2026-84387 · Severity: high · CVSS 7.2 · Published 2026-09-08

Technologies: Fortinet FortiSandbox. Vendors: Fortinet.

Executive brief

FortiSandbox is a malware analysis and sandboxing appliance used by enterprises to safely detonate and analyze suspicious files. A command injection vulnerability in its web interface allows a privileged attacker to execute arbitrary commands on the system through crafted HTTP requests, potentially compromising the integrity of threat analysis operations and lateral movement into the network.

Technical details

An improper neutralization of special elements in command strings (CWE-77 / command injection) exists in the FortiSandbox GUI component. The vulnerability is triggered via crafted HTTP requests and requires authenticated access (privileged user credentials). A successful exploit allows an attacker to execute unauthorized system commands with FortiSandbox process privileges. The vulnerability affects FortiSandbox 4.4.0–4.4.9, 5.0.0–5.0.6, and 5.2.0; patches are available (4.4.10+, 5.0.7+, 5.2.1+).

Affected products

  • Fortinet FortiSandbox 4.4.0 through 4.4.9, 5.0.0 through 5.0.6, 5.2.0

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: patched: FortiSandbox 4.4.10+, 5.0.7+, 5.2.1+ available

References

Related threats