CVE-2026-27316
published 2026-04-14CVE-2026-27316: A insufficiently protected credentials vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4 all versions, FortiSandbox PaaS 5.0.1…
low2.7CVSS 3.1
AVNACLPRHUINSUCLINAN
A insufficiently protected credentials vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4 all versions, FortiSandbox PaaS 5.0.1 through 5.0.5 may allow an authenticathed administrator to read LDAP server credentials via client-side inspection.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortisandbox | — | — |
| fortinet | fortisandbox | >= 4.4.0 < 5.0.6 | 5.0.6 |
| fortinet | fortisandbox | 4.4.0 – 4.4.9 | — |
| fortinet | fortisandbox | 5.0.0 – 5.0.5 | — |
| fortinet | fortisandbox_cloud | — | — |
| fortinet | fortisandbox_cloud | — | — |
| fortinet | fortisandbox_paas | — | — |
| fortinet | fortisandbox_paas | — | — |
| fortinet | fortisandbox_paas | — | — |
| fortinet | fortisandbox_paas | — | — |
| fortinet | fortisandbox_paas | — | — |
| fortinet | fortisandbox_paas | — | — |
| fortinet | fortisandbox_paas | — | — |
| fortinet | fortisandbox_paas | — | — |
| fortinet | fortisandbox_paas | — | — |
| fortinet | fortisandbox_paas | 5.0.1 – 5.0.5 | — |