CVE-2026-39812: Multiple Stored XSS
A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox PaaS 5.0.0 through 5.0.5, FortiSandbox PaaS 4.4.0 through 4.4.8, FortiSandbox PaaS 4.2 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>
Other sources
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiSandbox and FortiSandbox Cloud may allow a privileged attacker to perform a stored XSS attack via crafted HTTP requests.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39812?
CVE-2026-39812 has a severity rating of medium with a score of 4.8.
How do I fix CVE-2026-39812?
To fix CVE-2026-39812, upgrade to FortiSandbox version 5.0.6 or above, or 4.4.9 or above for earlier versions.
What does CVE-2026-39812 affect?
CVE-2026-39812 affects multiple versions of Fortinet FortiSandbox and FortiSandbox PaaS.
What type of vulnerability is CVE-2026-39812?
CVE-2026-39812 is a stored cross-site scripting (XSS) vulnerability.
What are the potential impacts of CVE-2026-39812?
CVE-2026-39812 may allow an attacker to execute arbitrary scripts in the context of a user's browser.