FG-IR-26-100: OS Command Injection through API endpoint
Published Apr 14, 2026
·Updated
An Improper Neutralization of Special Elements used in an OS Command ('OS command injection') vulnerability [CWE-78] in FortiSandbox may allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
Affected Software
1 affected componentFixes available
Fortinet FortiSandbox>=4.4.0<=4.4.8
Event History
Apr 14, 2026
Advisory Published
via FortiGuard·12:00 AM
Data Sourced
via FortiGuard·12:00 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of FG-IR-26-100?
The severity of FG-IR-26-100 is considered critical as it allows unauthenticated attackers to execute unauthorized commands.
2
How do I fix FG-IR-26-100?
To fix FG-IR-26-100, upgrade FortiSandbox to version 4.4.9 or later.
3
What impacts could FG-IR-26-100 have on my system?
FG-IR-26-100 could lead to unauthorized code execution, compromising system integrity and data confidentiality.
4
What versions of FortiSandbox are affected by FG-IR-26-100?
FortiSandbox versions from 4.4.0 to 4.4.8 are affected by FG-IR-26-100.
5
Is authentication required to exploit FG-IR-26-100?
No, exploitation of FG-IR-26-100 does not require authentication, making it highly dangerous.