CVE-2026-39808
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: a improper neutralization of special elements used in an os command ('os command injection') vulnerability in…
CISA federal remediation date Jul 19
Vulnerabilities · 152 days ago
FortiSandbox is exposed to full takeover if it is reachable from the internet. The standard response is to treat this as a patch-only issue, but unauthenticated auth bypass and OS command injection mean an attacker may not need credentials at all.
Fortinet patched CVE-2026-39813, a critical authentication bypass in the FortiSandbox JRPC API, and CVE-2026-39808, a critical OS command injection flaw. Both score 9.1 and can be triggered through crafted HTTP requests without authentication. Fortinet also fixed CVE-2026-22828 in FortiAnalyzer Cloud, a high-severity buffer overflow that can be reached without authentication, though Fortinet says exploitation would be difficult and would require access to another cloud component in the same entity.
The risk persists anywhere these products are exposed to untrusted networks. In FortiSandbox, the issue is not just access to the appliance but control of the sandbox itself, which can turn a security control into an entry point.
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: a improper neutralization of special elements used in an os command ('os command injection') vulnerability in…
CISA federal remediation date Jul 19
CVSS 9.8 CRITICAL: a path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through…
CVSS 8.1 HIGH: a heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer Cloud 7.6.2 through 7.6.4, FortiManager Cloud…
3 sources covering this story
Two vulnerabilities (CVE-2026-39813, CVE-2026-39808) in FortiSandbox could be exploited by unauthenticated attackers via HTTP requests.
Critical Fortinet sandbox bugs allow auth bypass and RCE
: No reports of active exploitation (yet)
Fortinet Patches Critical FortiSandbox Vulnerabilities
The flaws could allow attackers to bypass authentication or execute arbitrary code or commands via HTTP requests.
Part of the PlainSec briefing for 2026-04-16