FG-IR-26-096: OS command injection on vmimages update feature
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow a privileged attacker with super-admin profile and CLI access to execute unauthorized code or commands via crafted HTTP requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-26-096?
The severity of FG-IR-26-096 is critical due to its potential for OS command injection by privileged attackers.
How does FG-IR-26-096 exploit occur?
FG-IR-26-096 exploits occur when an attacker leverages improper neutralization of special elements in the OS command on the vmimages update feature.
Who is affected by FG-IR-26-096?
FG-IR-26-096 affects users of Fortinet's FortiSandbox Cloud with super-admin profile and CLI access.
How do I fix FG-IR-26-096?
To fix FG-IR-26-096, update to the latest version of FortiSandbox Cloud that addresses this vulnerability.
What is the impact of FG-IR-26-096 on FortiSandbox Cloud?
The impact of FG-IR-26-096 can allow unauthorized code execution, which may lead to system compromise and data loss.