CVE-2026-25836
published 2026-03-10CVE-2026-25836: An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox Cloud 5.0.4, FortiSandbox…
PriorityP356high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
1.76%
75.4th percentile
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox Cloud 5.0.4, FortiSandbox PaaS 5.0.4 may allow a privileged attacker with super-admin profile and CLI access to execute unauthorized code or commands via crafted HTTP requests.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortisandbox | — | — |
| fortinet | fortisandbox_cloud | — | — |
| fortinet | fortisandbox_paas | — | — |
| fortinet | fortisandboxcloud | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4j52-3x46-3m7g: An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox Cloud 5
ghsa_unreviewed·2026-03-10
CVE-2026-25836 [HIGH] CWE-78 GHSA-4j52-3x46-3m7g: An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox Cloud 5
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox Cloud 5.0.4 may allow a privileged attacker with super-admin profile and CLI access to execute unauthorized code or commands via crafted HTTP requests.
Fortinet
OS command injection on vmimages update feature
vendor_fortinet·2026-03-10·CVSS 7.2
CVE-2026-25836 [HIGH] CWE-78 OS command injection on vmimages update feature
FG-IR-26-096: OS command injection on vmimages update feature
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox Cloud 5.0.4 may allow a privileged attacker with super-admin profile and CLI access to execute unauthorized code or commands via crafted HTTP requests.
CVEs: CVE-2026-25836
CWEs: CWE-78
CVSS: 7.2 (high)
Affected products: FortiSandbox, FortiSandboxcloud, Fortinet
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-03-10
Published