CVE-2026-39808: OS Command Injection through API endpoint
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>
Other sources
An Improper Neutralization of Special Elements used in an OS Command ('OS command injection') vulnerability [CWE-78] in FortiSandbox may allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
— FortiGuard
Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Fortinet FortiSandbox PaaSto a version that resolves this vulnerability.Fixed in 5.0.2 - Upgrade
Upgrade
Fortinet FortiSandboxto a version that resolves this vulnerability.Fixed in 4.4.9 - Compensating control
Evaluate each asset's internet exposure and ensure adherence to CISA BOD 26-04 patching guidelines.
- Compensating control
Follow applicable BOD 26-04 guidance for cloud services; if mitigations are unavailable, discontinue use of FortiSandbox.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39808?
CVE-2026-39808 is classified as a critical vulnerability that allows for OS command injection.
How do I fix CVE-2026-39808?
To mitigate CVE-2026-39808, upgrade FortiSandbox to version 4.4.9 or later.
What versions of FortiSandbox are affected by CVE-2026-39808?
FortiSandbox versions 4.4.0 through 4.4.8 are affected by CVE-2026-39808.
What can an attacker achieve by exploiting CVE-2026-39808?
An attacker can execute unauthorized code or commands on the affected FortiSandbox systems through CVE-2026-39808.
What is OS command injection in the context of CVE-2026-39808?
OS command injection in CVE-2026-39808 refers to the vulnerability that allows attackers to manipulate system commands through improperly handled input.