CVE-2026-84387: Command Injection
A improper neutralization of special elements used in a command ('command injection') vulnerability in Fortinet FortiSandbox 5.2.0, FortiSandbox 5.0.0 through 5.0.6, FortiSandbox 4.4.0 through 4.4.9 may allow attacker to execute unauthorized code or commands via <insert attack vector here>
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Fortinet FortiSandboxto a version that resolves this vulnerability.Fixed in 5.0.7 - Upgrade
Upgrade
Fortinet FortiSandboxto a version that resolves this vulnerability.Fixed in 5.2.1 - Upgrade
Upgrade
Fortinet FortiSandboxto a version that resolves this vulnerability.Fixed in 4.4.10
Event History
Frequently Asked Questions
Which deployments are identified as affected?
The affected releases listed are FortiSandbox 5.2.0, FortiSandbox 5.0.0 through 5.0.6, and FortiSandbox 4.4.0 through 4.4.9.
What level of access does an attacker need?
The supplied CVSS vector specifies high privileges (PR:H). It does not identify the specific privileged role or the attack vector required to reach the vulnerable command handling.
Does exploitation require user interaction?
No. The CVSS vector indicates that user interaction is not required (UI:N).
What impact could successful exploitation have?
Successful exploitation may allow execution of unauthorized code or commands. The supplied CVSS vector rates confidentiality, integrity, and availability impact as high.