CVE-2026-25089

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox

Severity
Critical 9.1
CVSS 3.1
Exploited
Yes — in CISA KEV
Added Jul 16, 2026
EPSS
0.761
99.5th percentile
Discovered by
Vendor
Vendor advisory field
Published
Jun 9, 2026
Assigned by fortinet

Description

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests

Weakness: CWE-78

Affected products

Vendor Product Category Matched by
Fortinet FortiSandbox Threat Detection & Sandbox cna-assigner
Vendor-reported products (3)
  • Fortinet · FortiSandbox
  • Fortinet · FortiSandbox Cloud
  • Fortinet · FortiSandbox PaaS

Credit

Internally discovered and reported by Adham El Karn of Fortinet Product Security team.

Vendor remediation

Upgrade to upcoming FortiSandbox version 5.2.0 or above Upgrade to FortiSandbox version 5.0.6 or above Upgrade to FortiSandbox version 4.4.9 or above Upgrade to upcoming FortiSandbox PaaS version 5.2.0 or above Upgrade to FortiSandbox PaaS version 5.0.6 or above Fortinet remediated this issue in FortiSandbox Cloud version 5.2.0 (not released) and hence customers do not need to perform any action. Fortinet remediated this issue in FortiSandbox Cloud version 5.0.6 (not released) and hence customers do not need to perform any action.

Something wrong here?