Vulnerabilities & Exploits · Web App Attack

FortiSandbox Bugs Let Attackers Skip Login and Run Commands

FortiSandbox is exposed to full takeover if it is reachable from the internet. The standard response is to treat this as a patch-only issue, but unauthenticated auth bypass and OS command injection mean an attacker may not need credentials at all.

Fortinet patched CVE-2026-39813, a critical authentication bypass in the FortiSandbox JRPC API, and CVE-2026-39808, a critical OS command injection flaw. Both score 9.1 and can be triggered through crafted HTTP requests without authentication. Fortinet also fixed CVE-2026-22828 in FortiAnalyzer Cloud, a high-severity buffer overflow that can be reached without authentication, though Fortinet says exploitation would be difficult and would require access to another cloud component in the same entity.

The risk persists anywhere these products are exposed to untrusted networks. In FortiSandbox, the issue is not just access to the appliance but control of the sandbox itself, which can turn a security control into an entry point.

3 sources · Apr 16

CVE-2026-39808

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: a improper neutralization of special elements used in an os command ('os command injection') vulnerability in…

CISA federal remediation date Jul 19

CVE-2026-39813

NVD KEV

CVSS 9.8 CRITICAL: a path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through…

CVE-2026-22828

NVD KEV

CVSS 8.1 HIGH: a heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer Cloud 7.6.2 through 7.6.4, FortiManager Cloud…

Timeline

Sources

Vendor digest: Fortinet

Part of the PlainSec briefing for 2026-04-16

Every edition of this story: FortiSandbox Bugs Let Attackers Skip Login and Run Commands

More from today