CVE-2026-25836OS Command Injection in Fortinet Fortisandbox Cloud

Severity
7.2HIGHNVD
EPSS
0.1%
top 82.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 10

Description

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox Cloud 5.0.4 may allow a privileged attacker with super-admin profile and CLI access to execute unauthorized code or commands via crafted HTTP requests.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-4j52-3x46-3m7g: An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox Cloud 52026-03-10
CVEList
CVE-2026-25836: An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox Cloud 52026-03-10

📋Vendor Advisories

1
Fortinet
OS command injection on vmimages update feature2026-03-10
CVE-2026-25836 — OS Command Injection in Fortinet | cvebase