ZDI-26-048: Fortinet FortiSandbox fortisandbox Server-Side Request Forgery Remote Code Execution Vulnerability
Published Jan 28, 2026
·Updated
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Fortinet FortiSandbox. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2025-67685.
Affected Software
1 affected component
Fortinet FortiSandbox
Event History
Jan 28, 2026
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-26-048?
The severity of ZDI-26-048 is high due to its potential for remote code execution.
2
How do I fix ZDI-26-048?
To fix ZDI-26-048, ensure that you apply the latest security patches provided by Fortinet for FortiSandbox.
3
What are the main effects of ZDI-26-048?
ZDI-26-048 allows attackers to disclose sensitive information and potentially execute remote code.
4
Is authentication required to exploit ZDI-26-048?
Yes, authentication is required to exploit ZDI-26-048.
5
Which software is affected by ZDI-26-048?
ZDI-26-048 affects Fortinet FortiSandbox installations.