FG-IR-26-113: Credential disclosure in LDAP configuration web page.
Published Apr 14, 2026
·Updated
An Insufficiently protected credentials vulnerability [CWE-522] in FortiSanbox and FortiSanbox PaaS GUI may allow an authenticated administrator to read LDAP server credentials via client-side inspection.
Affected Software
3 affected componentsFixes available
Fortinet FortiSandbox>=5.0.0<=5.0.5
Fortinet FortiSandbox>=4.4
Fortinet FortiSandbox PaaS>=5.0.1<=5.0.5
Event History
Apr 14, 2026
Advisory Published
via FortiGuard·12:00 AM
Data Sourced
via FortiGuard·12:00 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of FG-IR-26-113?
The severity of FG-IR-26-113 is considered high due to the potential for credential disclosure.
2
How do I fix FG-IR-26-113?
To fix FG-IR-26-113, upgrade FortiSandbox to version 5.0.6 or later.
3
Which products are affected by FG-IR-26-113?
FG-IR-26-113 affects FortiSandbox versions 4.4 and from 5.0.0 to 5.0.5 as well as FortiSandbox PaaS from 5.0.1 to 5.0.5.
4
What type of vulnerability is FG-IR-26-113?
FG-IR-26-113 is classified as an insufficiently protected credentials vulnerability as per CWE-522.
5
Who can exploit FG-IR-26-113?
An authenticated administrator can exploit FG-IR-26-113 to read LDAP server credentials via client-side inspection.