FG-IR-26-136: Incorrect global authorization
Published May 12, 2026
·Updated
A missing authorization vulnerability [CWE-862] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to execute unauthorized code or commands via HTTP requests.
Affected Software
12 affected componentsFixes available
Fortinet FortiSandbox>=5.0.0<=5.0.1
Fortinet FortiSandbox>=4.4.0<=4.4.8
Fortinet FortiSandbox Cloud>=5.0.2<=5.0.5
Fortinet FortiSandbox PaaS>=23.4
Fortinet FortiSandbox PaaS>=23.3
Fortinet FortiSandbox PaaS>=23.1
Fortinet FortiSandbox PaaS>=22.2
Fortinet FortiSandbox PaaS>=22.1
Fortinet FortiSandbox PaaS>=21.4
Fortinet FortiSandbox PaaS>=21.3
Fortinet FortiSandbox PaaS>=5.0.0<=5.0.1
Fortinet FortiSandbox PaaS>=4.4.5<=4.4.8
Event History
May 12, 2026
Advisory Published
via FortiGuard·12:00 AM
Data Sourced
via FortiGuard·12:00 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of FG-IR-26-136?
The severity of FG-IR-26-136 is categorized as high due to the potential for unauthorized code execution.
2
How do I fix FG-IR-26-136?
To fix FG-IR-26-136, upgrade FortiSandbox to the latest versions as specified in the advisory.
3
What products are affected by FG-IR-26-136?
FG-IR-26-136 affects multiple versions of FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS.
4
Can FG-IR-26-136 be exploited remotely?
Yes, FG-IR-26-136 can be exploited remotely by an unauthenticated attacker via HTTP requests.
5
What type of vulnerability is FG-IR-26-136?
FG-IR-26-136 is an authorization vulnerability classified under CWE-862, leading to potential unauthorized actions.