CVE-2021-26097: [FortiSandbox] - Command injection in FSA's web interface
An improper neutralization of special elements used in an OS Command vulnerability in FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.0 through 3.0.6 may allow an authenticated attacker with access to the web GUI to execute unauthorized code or commands via specifically crafted HTTP requests.
Other sources
An improper neutralization of special elements used in an OS Command vulnerability in FortiSandbox may allow an authenticated attacker with access to the web GUI to execute unauthorized code or commands via specifically crafted HTTP requests.
— FortiGuard
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-26097?
CVE-2021-26097 is an OS Command vulnerability in FortiSandbox 3.0.0 through 3.2.2, allowing an attacker to execute unauthorized code or commands through crafted HTTP requests.
How severe is CVE-2021-26097?
CVE-2021-26097 has a severity score of 8.8 (high).
Which versions of FortiSandbox are affected by CVE-2021-26097?
FortiSandbox versions 3.0.0 through 3.2.2 are affected by CVE-2021-26097.
How can an attacker exploit CVE-2021-26097?
An authenticated attacker with access to the web GUI can exploit CVE-2021-26097 by sending specially crafted HTTP requests.
Is there a fix for CVE-2021-26097?
Yes, it is recommended to update FortiSandbox to version 3.2.3 or higher to mitigate the vulnerability.