CVE-2026-25691: Arbitrary directory delete on vmimages delete feature
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4, FortiSandbox PaaS 5.0.4 may allow a privileged attacker with super-admin profile and CLI access to delete an arbitrary directory via HTTP crafted requests.
Other sources
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS and FortiSandbox Cloud WEB UI may allow a privileged attacker with super-admin profile and CLI access to delete an arbitrary directory via HTTP crafted requests.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25691?
CVE-2026-25691 has a severity rating of medium with a score of 6.7.
How do I fix CVE-2026-25691?
To fix CVE-2026-25691, upgrade to FortiSandbox version 5.0.6 or above, version 4.4.9 or above, or FortiSandbox Cloud version 5.0.5 and later.
What type of vulnerability is CVE-2026-25691?
CVE-2026-25691 is a path traversal vulnerability that allows arbitrary directory deletion.
Which Fortinet products are affected by CVE-2026-25691?
CVE-2026-25691 affects Fortinet FortiSandbox versions 5.0.0 to 5.0.5, 4.4.0 to 4.4.8, and 4.2 all versions, as well as FortiSandbox Cloud and PaaS version 5.0.4.
What is the attack vector for CVE-2026-25691?
CVE-2026-25691 can be exploited by a privileged attacker with super-user access.