CVE-2026-26084

A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 ma

Severity
High 8.9
CVSS 3.1
Exploited
Not listed
EPSS
0.002
15.2th percentile
Discovered by
Vendor
Vendor advisory acknowledgement
Published
Sep 8, 2026
Assigned by fortinet

Description

A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests.

Weakness: CWE-284

Affected products

Vendor Product Category Matched by
Fortinet FortiSandbox Threat Detection & Sandbox cna-assigner
Vendor-reported products (3)
  • Fortinet · FortiSandbox PaaS
  • Fortinet · FortiSandbox
  • Fortinet · FortiSandbox Cloud

Credit

Internally discovered and reported by Adham El karn of Fortinet Product Security team.

Vendor remediation

Upgrade to FortiSandbox version 5.2.0 or above Upgrade to FortiSandbox version 5.0.6 or above Upgrade to FortiSandbox version 4.4.9 or above Upgrade to FortiSandbox Cloud version 5.0.6 or above Upgrade to FortiSandbox PaaS version 5.2.0 or above Upgrade to FortiSandbox PaaS version 5.0.6 or above Upgrade to FortiSandbox PaaS version 4.4.9 or above

Something wrong here?