CVE-2026-26084
8.9Fortinet · FortiSandbox
An improper access control vulnerability in various Fortinet FortiSandbox products allows unauthenticated attackers to access sensitive information via crafted HTTP requests.
Executive summary
An unauthenticated remote attacker can exploit an improper access control vulnerability in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS to potentially access sensitive information.
Vulnerability
The vulnerability arises from improper access control, allowing an unauthenticated attacker to send crafted HTTP requests to the target system to bypass security restrictions and access sensitive information.
Business impact
The vulnerability carries a CVSS score of 8.9, indicating a high level of severity due to the lack of required authentication and the potential for significant information disclosure. Unauthorized access to a sandbox environment may expose sensitive payloads, internal network configurations, or credentials, leading to a broader compromise of the organization's security infrastructure and potential regulatory non-compliance.
Remediation
Immediate Action: Upgrade to FortiSandbox version 5.2.0, 5.0.6, 4.4.9, or higher, depending on the specific product line and current deployment version, as specified in the vendor advisory.
Proactive Monitoring: Monitor network ingress and egress logs for suspicious HTTP requests targeting the FortiSandbox management interface or API endpoints.
Compensating Controls: Implement strict network access control lists (ACLs) to limit access to the FortiSandbox management interface to trusted administrative IP addresses only.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS score and the ability for unauthenticated attackers to interact with the device, this vulnerability poses a significant risk to perimeter security. Administrators should prioritize the application of the vendor-provided patches across all affected FortiSandbox environments immediately to prevent unauthorized access to sensitive internal data.
More Fortinet CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section