CVE-2026-27316: Credential disclosure in LDAP configuration web page.
A insufficiently protected credentials vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4 all versions, FortiSandbox PaaS 5.0.1 through 5.0.5 may allow an authenticathed administrator to read LDAP server credentials via client-side inspection.
Other sources
An Insufficiently protected credentials vulnerability [CWE-522] in FortiSanbox and FortiSanbox PaaS GUI may allow an authenticated administrator to read LDAP server credentials via client-side inspection.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27316?
CVE-2026-27316 has been classified with a severity that may allow an authenticated administrator to view sensitive LDAP credentials.
How do I fix CVE-2026-27316?
To fix CVE-2026-27316, upgrade FortiSandbox to version 5.0.6 or later for affected versions.
Which versions are affected by CVE-2026-27316?
CVE-2026-27316 affects Fortinet FortiSandbox versions 5.0.0 to 5.0.5 and all versions of FortiSandbox 4.4.
What are the implications of CVE-2026-27316?
The implications of CVE-2026-27316 include potential unauthorized access to LDAP credentials, leading to further security breaches.
Who should be concerned about CVE-2026-27316?
Administrators using vulnerable versions of FortiSandbox should be concerned about CVE-2026-27316 and take immediate action to upgrade.