CVE-2026-26084: Critical severity Fortinet FortiSandbox vulnerability
A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FortiSandboxto a version that resolves this vulnerability.Fixed in 4.4.9 or above - Upgrade
Upgrade
FortiSandboxto a version that resolves this vulnerability.Fixed in 5.0.6 or above - Upgrade
Upgrade
FortiSandboxto a version that resolves this vulnerability.Fixed in 5.2.0 or above - Upgrade
Upgrade
FortiSandbox Cloudto a version that resolves this vulnerability.Fixed in 5.0.6 or above - Upgrade
Upgrade
FortiSandbox PaaSto a version that resolves this vulnerability.Fixed in 4.4.9 or above - Upgrade
Upgrade
FortiSandbox PaaSto a version that resolves this vulnerability.Fixed in 5.0.6 or above - Upgrade
Upgrade
FortiSandbox PaaSto a version that resolves this vulnerability.Fixed in 5.2.0 or above
Event History
Frequently Asked Questions
Which deployments are affected?
Affected versions are FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, and FortiSandbox PaaS 5.0.4 through 5.0.5.
Does exploitation require authentication or user interaction?
No. The supplied vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction required.
What can an attacker do if exploitation succeeds?
An attacker may access sensitive information by sending crafted HTTP requests. The supplied severity vector also indicates low confidentiality and integrity impact and high availability impact, with scope changed.