FG-IR-25-783: SSRF in GUI console
Published Jan 13, 2026
·Updated
A Server-Side Request Forgery (SSRF) vulnerability [CWE-918] in FortiSandbox may allow an authenticated attacker to proxy internal requests limited to plaintext endpoints only via crafted HTTP requests.
Affected Software
4 affected componentsFixes available
Fortinet FortiSandbox>=5.0.0<=5.0.4
Fortinet FortiSandbox>=4.4
Fortinet FortiSandbox>=4.2
Fortinet FortiSandbox>=4.0
Event History
Jan 13, 2026
Advisory Published
via FortiGuard·12:00 AM
Data Sourced
via FortiGuard·12:00 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of FG-IR-25-783?
The FG-IR-25-783 vulnerability is categorized as a Server-Side Request Forgery (SSRF) which can lead to potential internal network exploitation.
2
How do I fix FG-IR-25-783?
To remediate FG-IR-25-783, upgrade to FortiSandbox version 5.0.5 or higher.
3
What type of requests does FG-IR-25-783 affect?
FG-IR-25-783 affects plaintext HTTP requests that are proxied by an authenticated attacker.
4
Which versions of FortiSandbox are affected by FG-IR-25-783?
FortiSandbox versions 4.0, 4.2, 4.4, and 5.0.0 to 5.0.4 are impacted by FG-IR-25-783.
5
Who can exploit FG-IR-25-783?
An authenticated attacker can exploit FG-IR-25-783 to perform Server-Side Request Forgery attacks.