cbcvebase.

Fortinet Fortisandbox vulnerabilities

60 known vulnerabilities affecting fortinet/fortisandbox.

Total CVEs
60
CISA KEV
2
actively exploited
Public exploits
2
Exploited in wild
3
Severity breakdown
CRITICAL6HIGH24MEDIUM28LOW2

Vulnerabilities

Page 1 of 3
CVE-2026-39808P1CRITICALCVSS 9.8KEVPoC≥ 4.4.0, ≤ 4.4.92026-04-14
CVE-2026-39808 [CRITICAL] CWE-78 CVE-2026-39808: A improper neutralization of special elements used in an os command ('os command injection') vulnera A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via
nvd
CVE-2026-25089P1CRITICALCVSS 9.8KEV≥ 4.2.0, ≤ 4.2.8≥ 4.4.0, < 4.4.9+4 more2026-06-09
CVE-2026-25089 [CRITICAL] CWE-78 CVE-2026-25089: A improper neutralization of special elements used in an os command ('os command injection') vulnera A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unaut
nvd
CVE-2026-39813P1CRITICALCVSS 9.8ExploitedPoC≥ 4.4.0, < 4.4.9≥ 5.0.0, < 5.0.6+2 more2026-04-14
CVE-2026-39813 [CRITICAL] CWE-24 CVE-2026-39813: A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSand A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via
nvd
CVE-2025-53949P2HIGHCVSS 8.8≥ 4.0.0, ≤ 4.0.6≥ 4.2.0, ≤ 4.2.8+3 more2025-12-09
CVE-2025-53949 [HIGH] CWE-78 CVE-2025-53949: An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an authenticated attacker to execute unauthorized code on the underlying
nvd
CVE-2026-26083P2CRITICALCVSS 9.8≥ 4.4.0, < 4.4.9≥ 5.0.0, < 5.0.2+3 more2026-05-12
CVE-2026-26083 [CRITICAL] CWE-862 CVE-2026-26083: A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4 A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 through 5.0.5, FortiSandbox PaaS 23.4 all versions, FortiSandbox PaaS 23.3 all versions, FortiSandbox PaaS 23.1 all versions, FortiSandbox PaaS 22.2 all versions, FortiSandbox PaaS 22.1 all versions, FortiS
nvd
CVE-2025-53679P2HIGHCVSS 7.2≥ 4.0.0, < 4.4.8≥ 5.0.0, < 5.0.3+4 more2025-12-09
CVE-2025-53679 [HIGH] CWE-78 CVE-2025-53679: An improper neutralization of special elements used in an OS command ('OS Command Injection') vulner An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions, FortiSandbox Cloud 24.1, FortiSandbox Cloud 23 all versions allows a remote privi
nvd
CVE-2024-21755P2HIGHCVSS 8.8≥ 4.0.0, < 4.0.5≥ 4.2.0, < 4.2.7+4 more2024-04-09
CVE-2024-21755 [HIGH] CWE-78 CVE-2024-21755: A improper neutralization of special elements used in an os command ('os command injection') vulnera A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.3, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 through 4.0.4 allows attacker to execute unauthorized code or commands via crafted requests..
nvd
CVE-2024-21756P2HIGHCVSS 8.8≥ 4.0.0, < 4.0.5≥ 4.2.0, < 4.2.7+4 more2024-04-09
CVE-2024-21756 [HIGH] CWE-78 CVE-2024-21756: A improper neutralization of special elements used in an os command ('os command injection') vulnera A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.3, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 through 4.0.4 allows attacker to execute unauthorized code or commands via crafted requests..
nvd
CVE-2025-52436P2CRITICALCVSS 9.6≥ 4.0.0, < 4.4.8≥ 5.0.0, < 5.0.2+4 more2026-02-10
CVE-2025-52436 [CRITICAL] CWE-79 CVE-2025-52436: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an unauthenticated attacker to execute commands via crafted requests.
nvd
CVE-2026-59835P2HIGHCVSS 8.6≥ 4.4.3, < 4.4.9≥ 5.0.0, < 5.0.3+2 more2026-07-14
CVE-2026-59835 [HIGH] CWE-668 CVE-2026-59835: A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, F A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests.
nvd
CVE-2024-27781P3CRITICALCVSS 9.0≥ 3.0.0, < 4.0.5≥ 4.2.0, < 4.2.7+7 more2025-02-11
CVE-2024-27781 [CRITICAL] CWE-79 CVE-2024-27781: An improper neutralization of input during web page generation ('cross-site scripting') vulnerabilit An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 through 4.0.4, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all versions allows an authenticated attacker to execut
nvd
CVE-2024-54026P2HIGHCVSS 8.8≥ 3.0.0, < 4.4.7≥ 4.4.0, ≤ 4.4.6+5 more2025-03-11
CVE-2024-54026 [HIGH] CWE-89 CVE-2024-54026: An improper neutralization of special elements used in an sql command ('sql injection') in Fortinet An improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiSandbox 4.4.0 through 4.4.6, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all versions, FortiSandbox Cloud 24.1 allows attacker to execute unauthorized co
nvd
CVE-2024-27778P2HIGHCVSS 8.8≥ 3.0.5, < 4.0.5≥ 4.2.0, < 4.2.7+7 more2025-01-14
CVE-2024-27778 [HIGH] CWE-78 CVE-2024-27778: An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerab An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 through 4.0.4, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0.5 through 3.0.7 allows an authenticated attacker with a
nvd
CVE-2024-52961P3HIGHCVSS 8.8≥ 3.0.0, < 4.0.6≥ 4.2.0, < 4.2.8+8 more2025-03-11
CVE-2024-52961 [HIGH] CWE-78 CVE-2024-52961: An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerab An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0.0, FortiSandbox 4.4.0 through 4.4.6, FortiSandbox 4.2.1 through 4.2.7, FortiSandbox 4.0.0 through 4.0.5, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all versions allows an authenticate
nvd
CVE-2024-54018P3HIGHCVSS 7.2≥ 3.2.0, < 4.4.6≥ 4.4.0, ≤ 4.4.4+3 more2025-03-11
CVE-2024-54018 [HIGH] CWE-78 CVE-2024-54018: Multiple improper neutralization of special elements used in an OS Command vulnerabilities [CWE-78] Multiple improper neutralization of special elements used in an OS Command vulnerabilities [CWE-78] in FortiSandbox before 4.4.5 allows a privileged attacker to execute unauthorized commands via crafted requests.
nvd
CVE-2021-26097P3HIGHCVSS 8.8fixed in 3.0.7≥ 3.1.0, < 3.1.5+1 more2021-08-04
CVE-2021-26097 [HIGH] CWE-78 CVE-2021-26097: An improper neutralization of special elements used in an OS Command vulnerability in FortiSandbox 3 An improper neutralization of special elements used in an OS Command vulnerability in FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.0 through 3.0.6 may allow an authenticated attacker with access to the web GUI to execute unauthorized code or commands via specifically crafted HTTP requests.
nvd
CVE-2024-31491P3HIGHCVSS 8.8≥ 4.2.0, < 4.2.7≥ 4.4.0, < 4.4.5+2 more2024-05-14
CVE-2024-31491 [HIGH] CWE-602 CVE-2024-31491: A client-side enforcement of server-side security vulnerability in Fortinet FortiSandbox 4.4.0 throu A client-side enforcement of server-side security vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6 allows attacker to execute unauthorized code or commands via HTTP requests.
nvd
CVE-2021-26105P3HIGHCVSS 8.8≥ 3.1.0, ≤ 3.1.4≥ 3.2.0, < 3.2.3+3 more2025-03-24
CVE-2021-26105 [HIGH] CWE-358 CVE-2021-26105: A stack-based buffer overflow vulnerability (CWE-121) in the profile parser of FortiSandbox version A stack-based buffer overflow vulnerability (CWE-121) in the profile parser of FortiSandbox version 3.2.2 and below, version 3.1.4 and below may allow an authenticated attacker to potentially execute unauthorized code or commands via specifically crafted HTTP requests.
nvd
CVE-2024-52960P3HIGHCVSS 8.8≥ 3.0.0, < 4.2.8≥ 4.4.0, < 4.4.7+7 more2025-03-11
CVE-2024-52960 [HIGH] CWE-602 CVE-2024-52960: A client-side enforcement of server-side security vulnerability [CWE-602] in Fortinet FortiSandbox v A client-side enforcement of server-side security vulnerability [CWE-602] in Fortinet FortiSandbox version 5.0.0, 4.4.0 through 4.4.6 and before 4.2.7 allows an authenticated attacker with at least read-only permission to execute unauthorized commands via crafted requests.
nvd
CVE-2022-27487P3HIGHCVSS 8.8≥ 2.5.0, < 3.2.4≥ 4.0.0, < 4.0.3+7 more2023-04-11
CVE-2022-27487 [HIGH] CWE-269 CVE-2022-27487: A improper privilege management in Fortinet FortiSandbox version 4.2.0 through 4.2.2, 4.0.0 through A improper privilege management in Fortinet FortiSandbox version 4.2.0 through 4.2.2, 4.0.0 through 4.0.2 and before 3.2.3 and FortiDeceptor version 4.1.0, 4.0.0 through 4.0.2 and before 3.3.3 allows a remote authenticated attacker to perform unauthorized API calls via crafted HTTP or HTTPS requests.
nvd