FortiSandbox Bugs Let Attackers Skip Login and Run Commands
FortiSandbox is exposed to full takeover if it is reachable from the internet. The standard response is to treat this as a patch-only issue, but unauthenticated auth bypass and OS command injection mean an attacker may not need credentials at all.
Fortinet patched CVE-2026-39813, a critical authentication bypass in the FortiSandbox JRPC API, and CVE-2026-39808, a critical OS command injection flaw. Both score 9.1 and can be triggered through crafted HTTP requests without authentication. Fortinet also fixed CVE-2026-22828 in FortiAnalyzer Cloud, a high-severity buffer overflow that can be reached without authentication, though Fortinet says exploitation would be difficult and would require access to another cloud component in the same entity.
The risk persists anywhere these products are exposed to untrusted networks. In FortiSandbox, the issue is not just access to the appliance but control of the sandbox itself, which can turn a security control into an entry point.