CVE-2026-39813: Unauthenticated Authentication bypass and Privilege escalation in FortiSandbox
A Path Traversal vulnerability [CWE-24] in FortiSandbox JRPC API may allow an unauthenticated attacker to bypass authentication via specially crafted HTTP requests.
Other sources
A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially crafted HTTP requests.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Fortinet FortiSandboxto a version that resolves this vulnerability.Fixed in 4.4.9 - Upgrade
Upgrade
Fortinet FortiSandboxto a version that resolves this vulnerability.Fixed in 5.0.6 - Upgrade
Upgrade
Fortinet FortiSandboxto a version that resolves this vulnerability.Fixed in 5.2.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39813?
CVE-2026-39813 has been classified as a critical vulnerability due to its potential for unauthenticated authentication bypass and privilege escalation.
How do I fix CVE-2026-39813?
To fix CVE-2026-39813, update FortiSandbox to version 5.0.6 or later for affected versions up to 5.0.5 and to version 4.4.9 or later for affected versions up to 4.4.8.
Who is affected by CVE-2026-39813?
CVE-2026-39813 affects FortiSandbox versions between 5.0.0 and 5.0.5 as well as versions between 4.4.0 and 4.4.8.
What type of attack can exploit CVE-2026-39813?
CVE-2026-39813 can be exploited by an unauthenticated attacker through specially crafted HTTP requests to bypass authentication.
What is the impact of CVE-2026-39813 on FortiSandbox?
The impact of CVE-2026-39813 includes the ability for attackers to gain unauthorized access and execute operations that should be restricted.