Vulnerabilità ed exploit · Attacco ad app web

FortiSandbox Bugs Let Attackers Skip Login and Run Commands

FortiSandbox is exposed to full takeover if it is reachable from the internet. The standard response is to treat this as a patch-only issue, but unauthenticated auth bypass and OS command injection mean an attacker may not need credentials at all.

Fortinet patched CVE-2026-39813, a critical authentication bypass in the FortiSandbox JRPC API, and CVE-2026-39808, a critical OS command injection flaw. Both score 9.1 and can be triggered through crafted HTTP requests without authentication. Fortinet also fixed CVE-2026-22828 in FortiAnalyzer Cloud, a high-severity buffer overflow that can be reached without authentication, though Fortinet says exploitation would be difficult and would require access to another cloud component in the same entity.

The risk persists anywhere these products are exposed to untrusted networks. In FortiSandbox, the issue is not just access to the appliance but control of the sandbox itself, which can turn a security control into an entry point.

3 fonti · 16 apr

CVE-2026-39808

NVD KEV

Sfruttamento noto · CISA KEV

CVSS 9.8 CRITICAL: a improper neutralization of special elements used in an os command ('os command injection') vulnerability in…

Data di correzione federale CISA 19 lug

CVE-2026-39813

NVD KEV

CVSS 9.8 CRITICAL: a path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through…

CVE-2026-22828

NVD KEV

CVSS 8.1 HIGH: a heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer Cloud 7.6.2 through 7.6.4, FortiManager Cloud…

Cronologia

Fonti

Riepilogo fornitore: Fortinet

Part of the PlainSec briefing for 2026-04-16

Every edition of this story: FortiSandbox Bugs Let Attackers Skip Login and Run Commands

Altro da oggi