CVE-2026-25836: OS command injection on vmimages update feature
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow a privileged attacker with super-admin profile and CLI access to execute unauthorized code or commands via crafted HTTP requests.
Other sources
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox Cloud 5.0.4, FortiSandbox PaaS 5.0.4 may allow a privileged attacker with super-admin profile and CLI access to execute unauthorized code or commands via crafted HTTP requests.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25836?
CVE-2026-25836 is considered a high severity vulnerability due to its potential for OS command injection.
How do I fix CVE-2026-25836?
To fix CVE-2026-25836, update your FortiSandbox Cloud to the latest version provided by Fortinet.
Who is affected by CVE-2026-25836?
Privileged attackers with a super-admin profile and CLI access on FortiSandbox Cloud are affected by CVE-2026-25836.
What does CVE-2026-25836 allow an attacker to do?
CVE-2026-25836 allows an attacker to execute unauthorized code or commands through OS command injection.
What systems are impacted by CVE-2026-25836?
CVE-2026-25836 impacts the Fortinet FortiSandbox Cloud product.