CVE-2026-39813
published 2026-04-14CVE-2026-39813: A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of…
PriorityP186critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
16.74%
96.7th percentile
A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortisandbox | — | — |
| fortinet | fortisandbox | >= 4.4.0 < 4.4.9 | 4.4.9 |
| fortinet | fortisandbox | 4.4.0 – 4.4.8 | — |
| fortinet | fortisandbox | >= 5.0.0 < 5.0.6 | 5.0.6 |
| fortinet | fortisandbox | 5.0.0 – 5.0.5 | — |
| fortinet | fortisandbox_cloud | — | — |
| fortinet | fortisandbox_cloud | — | — |
| fortinet | fortisandbox_cloud | 5.0.4 – 5.0.5 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2026-39813 is exploited via specially crafted HTTP requests targeting the FortiSandbox JRPC API to achieve authentication bypass through path traversal ↗
- →CVE-2026-39813 is being actively exploited in the wild alongside CVE-2026-39808 and CVE-2026-25089; prioritize detection and patching of all three on FortiSandbox appliances ↗
- →The vulnerability class is CWE-24 (path traversal '../filedir'); monitor HTTP requests to FortiSandbox JRPC API endpoints containing directory traversal sequences (e.g., '../') from unauthenticated sources ↗
- →Affected versions are FortiSandbox 5.0.0–5.0.5 and 4.4.0–4.4.8; use these version ranges to scope detection and asset inventory queries ↗
- ·Fortinet's PSIRT advisory rates CVE-2026-39813 as CVSS 9.8 (Critical), while The Hacker News reports a CVSS score of 9.1; analysts should use the vendor PSIRT score (9.8) as authoritative ↗
- ·No public working exploit for the co-exploited CVE-2026-25089 has been disclosed; the observed exploit shows signs of AI-generated code and is reportedly faulty, reducing immediate risk for that specific CVE ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Fortinet FortiSandbox/FortiSandbox Cloud up to 4.4.8/5.0.5 /filedir path traversal (FG-IR-26-112 / WID-SEC-2026-1094)
vuldb·2026-06-21·CVSS 9.8
CVE-2026-39813 [CRITICAL] Fortinet FortiSandbox/FortiSandbox Cloud up to 4.4.8/5.0.5 /filedir path traversal (FG-IR-26-112 / WID-SEC-2026-1094)
A vulnerability classified as critical has been found in Fortinet FortiSandbox and FortiSandbox Cloud up to 4.4.8/5.0.5. The affected element is an unknown function of the file /filedir. Performing a manipulation results in path traversal: '../filedir'.
This vulnerability was named CVE-2026-39813. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
GHSA
GHSA-5f64-p6cf-vvqg: A path traversal: '
ghsa_unreviewed·2026-04-14
CVE-2026-39813 [CRITICAL] CWE-24 GHSA-5f64-p6cf-vvqg: A path traversal: '
A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via
VulnCheck
Fortinet fortisandbox Path Traversal: '../filedir'
vulncheck·2026·CVSS 9.8
CVE-2026-39813 [CRITICAL] Fortinet fortisandbox Path Traversal: '../filedir'
Fortinet fortisandbox Path Traversal: '../filedir'
A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via
Affected: Fortinet fortisandbox
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://kevintel.com/CVE-2026-39813; https://x.com/DefusedCyber/status/2066575288503255274
Exploit PoC: https://vulncheck.com/xdb/22fedae75d77
Fortinet
Unauthenticated Authentication bypass and Privilege escalation in FortiSandbox
vendor_fortinet·2026-04-14·CVSS 9.8
CVE-2026-39813 [CRITICAL] CWE-24 Unauthenticated Authentication bypass and Privilege escalation in FortiSandbox
FG-IR-26-112: Unauthenticated Authentication bypass and Privilege escalation in FortiSandbox
A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via
CVEs: CVE-2026-39813
CWEs: CWE-24
CVSS: 9.8 (critical)
Affected products: FortiSandbox, Fortinet
No detection rules found.
No public exploits indexed.
Checkpoint
22nd June – Threat Intelligence Report
blogs_checkpoint·2026-06-22
CVE-2026-42824 22nd June – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 22nd June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 22nd June, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
Texas Parks and Wildlife Department has been affected by a third-party data breach involving its license system vendor. The incident exposed driver’s license information, passport numbers, emails, phone numbers, and residential addresses for 3,087,721 hunting and fishing license customers. Social Security numbers and payment dat
Bleepingcomputer
Critical Fortinet FortiSandbox flaws now exploited in attacks
blogs_bleepingcomputer·2026-06-16·CVSS 6.5
CVE-2026-39813 [MEDIUM] Critical Fortinet FortiSandbox flaws now exploited in attacks
## Critical Fortinet FortiSandbox flaws now exploited in attacks
## Sergiu Gatlan
Attackers are now exploiting several critical vulnerabilities in Fortinet's FortiSandbox cyber threat detection platform, according to threat intelligence company Defused.
Fortinet released security updates for these three critical-severity security flaws (tracked as CVE-2026-39813 , CVE-2026-39808 , and CVE-2026-25089 ) on April 14.
These flaws allow unauthenticated threat actors to escalate privileges and execute unauthorized code remotely through low-complexity command injection attacks that require no user interaction. To resolve these issues and block incoming attacks, admins must upgrade affected deployments to the latest released versions.
"We are observing exploitation of multiple Fortinet FortiS
Hackernews
Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week
blogs_hackernews·2026-06-16·CVSS 9.8
CVE-2026-39813 [CRITICAL] Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week
Bad actors are exploiting multiple security vulnerabilities in Fortinet FortiSandbox, according to threat intelligence firm Defused Cyber.
In a post shared on X, the company said it has observed exploitation of CVE-2026-39813, CVE-2026-39808 , and CVE-2026-25089 over the past 24 hours.
CVE-2026-39813 (CVSS score: 9.1) refers to a path traversal vulnerability in FortiSandbox JRPC API that could allow an unauthenticated attacker to bypass authentication via specially crafted HTTP requests.
The second flaw, CVE-2026-39808 (CVSS score: 9.1), is a case o
Hackernews
⚡ Weekly Recap: Vercel Hack, Push Fraud, QEMU Abused, New Android RATs Emerge & More
blogs_hackernews·2026-04-20
CVE-2026-20184 ⚡ Weekly Recap: Vercel Hack, Push Fraud, QEMU Abused, New Android RATs Emerge & More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Vercel Hack, Push Fraud, QEMU Abused, New Android RATs Emerge & More
Monday’s recap shows the same pattern in different places. A third-party tool becomes a way in, then leads to internal access. A trusted download path is briefly swapped to deliver malware. Browser extensions act normally while pulling data and running code. Even update channels are used to push payloads. It’s not breaking systems—it’s bending trust.
There’s also a shift in how attacks run. Slower check-ins, multi-stage payloads, andmore code kept in memory. Attackers lean on real tools and normal workflows instead of custom builds. Some cas
Hackernews
April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and More
blogs_hackernews·2026-04-15·CVSS 9.9
[CRITICAL] April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and More
A number of critical vulnerabilities impacting products from Adobe, Fortinet, Microsoft, and SAP have taken center stage in April's Patch Tuesday releases.
Topping the list is an SQL injection vulnerability impacting SAP Business Planning and Consolidation and SAP Business Warehouse ( CVE-2026-27681 , CVSS score: 9.9) that could result in the execution of arbitrary database commands.
"The vulnerable ABAP program allows a low-privileged user to upload a file with arbitrary SQL statements that will then be executed," Onapsis said in an a
2026-04-14
Published
Exploited in the wild