FG-IR-26-145: Unauthenticated VNC access exposed on all interfaces
Published Jul 14, 2026
·Updated
An Exposure of Resource to Wrong Sphere vulnerability [CWE-668] in FortiSandbox may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests.
Affected Software
2 affected componentsFixes available
Fortinet FortiSandbox>=5.0.0<=5.0.2
Fortinet FortiSandbox>=4.4.3<=4.4.8
Event History
Jul 14, 2026
Advisory Published
via FortiGuard·12:00 AM
Data Sourced
via FortiGuard·12:00 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of FG-IR-26-145?
The severity of FG-IR-26-145 is rated as high with a score of 7.7.
2
How do I fix FG-IR-26-145?
To fix FG-IR-26-145, ensure that VNC access is restricted and that appropriate authentication measures are implemented.
3
What systems are affected by FG-IR-26-145?
FG-IR-26-145 affects Fortinet FortiSandbox systems that expose VNC access.
4
What type of vulnerability is FG-IR-26-145?
FG-IR-26-145 is classified as an Exposure of Resource to Wrong Sphere vulnerability, specifically CWE-668.
5
What is the risk associated with FG-IR-26-145?
The risk associated with FG-IR-26-145 is medium, with a risk score of 61.