FG-IR-26-112: Unauthenticated Authentication bypass and Privilege escalation in FortiSandbox
Published Apr 14, 2026
·Updated
A Path Traversal vulnerability [CWE-24] in FortiSandbox JRPC API may allow an unauthenticated attacker to bypass authentication via specially crafted HTTP requests.
Affected Software
2 affected componentsFixes available
Fortinet FortiSandbox>=5.0.0<=5.0.5
Fortinet FortiSandbox>=4.4.0<=4.4.8
Event History
Apr 14, 2026
Advisory Published
via FortiGuard·12:00 AM
Data Sourced
via FortiGuard·12:00 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of FG-IR-26-112?
The severity of FG-IR-26-112 is high due to the potential for unauthenticated authentication bypass and privilege escalation.
2
How do I fix FG-IR-26-112?
To fix FG-IR-26-112, upgrade FortiSandbox to version 5.0.6 or 4.4.9 or later.
3
What software is affected by FG-IR-26-112?
Fortinet FortiSandbox versions 5.0.0 to 5.0.5 and 4.4.0 to 4.4.8 are affected by FG-IR-26-112.
4
Can FG-IR-26-112 be exploited remotely?
Yes, FG-IR-26-112 can be exploited remotely by an unauthenticated attacker via specially crafted HTTP requests.
5
What type of vulnerability is FG-IR-26-112?
FG-IR-26-112 is classified as a Path Traversal vulnerability, which can lead to authentication bypass.