cbcvebase.
CVE-2026-39813
published 2026-04-14

CVE-2026-39813: A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of…

PriorityP186critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
16.74%
96.7th percentile
A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via

Affected

9 ranges
VendorProductVersion rangeFixed in
fortinetfortinet
fortinetfortisandbox
fortinetfortisandbox>= 4.4.0 < 4.4.94.4.9
fortinetfortisandbox4.4.0 – 4.4.8
fortinetfortisandbox>= 5.0.0 < 5.0.65.0.6
fortinetfortisandbox5.0.0 – 5.0.5
fortinetfortisandbox_cloud
fortinetfortisandbox_cloud
fortinetfortisandbox_cloud5.0.4 – 5.0.5

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2026-39813 is exploited via specially crafted HTTP requests targeting the FortiSandbox JRPC API to achieve authentication bypass through path traversal
  • CVE-2026-39813 is being actively exploited in the wild alongside CVE-2026-39808 and CVE-2026-25089; prioritize detection and patching of all three on FortiSandbox appliances
  • The vulnerability class is CWE-24 (path traversal '../filedir'); monitor HTTP requests to FortiSandbox JRPC API endpoints containing directory traversal sequences (e.g., '../') from unauthenticated sources
  • Affected versions are FortiSandbox 5.0.0–5.0.5 and 4.4.0–4.4.8; use these version ranges to scope detection and asset inventory queries
  • ·Fortinet's PSIRT advisory rates CVE-2026-39813 as CVSS 9.8 (Critical), while The Hacker News reports a CVSS score of 9.1; analysts should use the vendor PSIRT score (9.8) as authoritative
  • ·No public working exploit for the co-exploited CVE-2026-25089 has been disclosed; the observed exploit shows signs of AI-generated code and is reportedly faulty, reducing immediate risk for that specific CVE

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.