CVE-2026-39808

9.5 CISA KEV

Fortinet · FortiSandbox

Fortinet FortiSandbox is vulnerable to OS command injection, allowing unauthenticated attackers to execute unauthorized code on the appliance.

Executive summary

A critical OS command injection vulnerability in Fortinet FortiSandbox allows unauthenticated remote attackers to execute arbitrary code with elevated privileges.

Vulnerability

This is an OS command injection flaw (CWE-78) where insufficient neutralization of special elements allows attackers to execute unauthorized commands. The vulnerability is remotely exploitable without authentication, making it highly dangerous.

Business impact

The CVSS score of 9.8 justifies the critical status of this vulnerability. An attacker exploiting this flaw gains complete control over the security appliance, which can be used to bypass security policies, intercept internal traffic, or serve as a beachhead for lateral movement within the enterprise network.

Remediation

Immediate Action: Upgrade to FortiSandbox version 4.4.9 or above, or FortiSandbox PaaS version 5.0.2 or above, as recommended by the vendor.

Proactive Monitoring: Monitor for unexpected command execution patterns or unauthorized changes to system configurations via the management interface.

Compensating Controls: Restrict management interface access to authorized administrative IP addresses via ACLs to prevent unauthenticated access.

Exploitation status

Public Exploit Available: Yes — multiple proof-of-concept repositories exist on GitHub.

Analyst recommendation

Given the critical nature of this vulnerability and the availability of public proof-of-concept code, immediate patching is mandatory. Organizations should verify their versions against the vendor's advisory and apply the updates as the highest priority to prevent potential compromise.

More Fortinet CVEs