FG-IR-26-109: Reflected XSS in Operation Center
Published Apr 14, 2026
·Updated
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiSandbox and FortiSandbox Cloud may allow an attacker to perform an XSS attack via crafted HTTP requests.
Affected Software
2 affected componentsFixes available
Fortinet FortiSandbox>=5.0.0<=5.0.4
Fortinet FortiSandbox PaaS>=5.0.0<=5.0.4
Event History
Apr 14, 2026
Advisory Published
via FortiGuard·12:00 AM
Data Sourced
via FortiGuard·12:00 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of FG-IR-26-109?
The severity of FG-IR-26-109 is classified as medium with a risk score of 4.9.
2
How do I fix FG-IR-26-109?
To fix FG-IR-26-109, ensure that your FortiSandbox or FortiSandbox Cloud is updated to the latest version that addresses the reflected XSS vulnerability.
3
What type of vulnerability is FG-IR-26-109?
FG-IR-26-109 is a reflected cross-site scripting (XSS) vulnerability categorized under CWE-79.
4
What systems are affected by FG-IR-26-109?
FG-IR-26-109 affects Fortinet FortiSandbox and Fortinet FortiSandbox PaaS.
5
What actions can an attacker perform using FG-IR-26-109?
An attacker can leverage FG-IR-26-109 to execute crafted HTTP requests, potentially leading to an XSS attack.