Fortinet Fortisandbox Cloud vulnerabilities
10 known vulnerabilities affecting fortinet/fortisandbox_cloud.
Total CVEs
10
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
2
Severity breakdown
CRITICAL3HIGH3MEDIUM3LOW1
Vulnerabilities
Page 1 of 1
CVE-2026-25089P1CRITICALCVSS 9.8KEV≥ 5.0.4, < 5.0.6≥ 5.0.4, ≤ 5.0.52026-06-09
CVE-2026-25089 [CRITICAL] CWE-78 CVE-2026-25089: A improper neutralization of special elements used in an os command ('os command injection') vulnera
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unaut
nvd
CVE-2026-39813P1CRITICALCVSS 9.8ExploitedPoCv24.1v23.4+1 more2026-04-14
CVE-2026-39813 [CRITICAL] CWE-24 CVE-2026-39813: A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSand
A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via
nvd
CVE-2026-26083P2CRITICALCVSS 9.8≥ 5.0.2, < 5.0.6≥ 23.1.4245, ≤ 23.4.4374+3 more2026-05-12
CVE-2026-26083 [CRITICAL] CWE-862 CVE-2026-26083: A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4
A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 through 5.0.5, FortiSandbox PaaS 23.4 all versions, FortiSandbox PaaS 23.3 all versions, FortiSandbox PaaS 23.1 all versions, FortiSandbox PaaS 22.2 all versions, FortiSandbox PaaS 22.1 all versions, FortiS
nvd
CVE-2025-53679P2HIGHCVSS 7.2≥ 23.1.4245, < 23.4.4374v24.1.4436+2 more2025-12-09
CVE-2025-53679 [HIGH] CWE-78 CVE-2025-53679: An improper neutralization of special elements used in an OS command ('OS Command Injection') vulner
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions, FortiSandbox Cloud 24.1, FortiSandbox Cloud 23 all versions allows a remote privi
nvd
CVE-2024-54026P2HIGHCVSS 8.8v24.12025-03-11
CVE-2024-54026 [HIGH] CWE-89 CVE-2024-54026: An improper neutralization of special elements used in an sql command ('sql injection') in Fortinet
An improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiSandbox 4.4.0 through 4.4.6, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all versions, FortiSandbox Cloud 24.1 allows attacker to execute unauthorized co
nvd
CVE-2026-25836P3HIGHCVSS 7.2v5.0.42026-03-10
CVE-2026-25836 [HIGH] CWE-78 CVE-2026-25836: An improper neutralization of special elements used in an os command ('os command injection') vulner
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox Cloud 5.0.4, FortiSandbox PaaS 5.0.4 may allow a privileged attacker with super-admin profile and CLI access to execute unauthorized code or commands via crafted HTTP requests.
nvd
CVE-2026-25691P3MEDIUMCVSS 6.7v5.0.42026-04-14
CVE-2026-25691 [MEDIUM] CWE-22 CVE-2026-25691: A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fo
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4, FortiSandbox PaaS 5.0.4 may allow a privileged attacker with super-admin profile and CLI access to delete an arbitrary d
nvd
CVE-2025-61886P4MEDIUMCVSS 5.4v5.0.42026-04-14
CVE-2025-61886 [MEDIUM] CWE-79 CVE-2025-61886: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.4, FortiSandbox PaaS 5.0.0 through 5.0.4 may allow an attacker to perform an XSS attack via crafted HTTP requests.
nvd
CVE-2026-39812P4MEDIUMCVSS 4.8≥ 22.2.4134, ≤ 23.1.4260≥ 23.3.4329, ≤ 24.1.4436+2 more2026-04-14
CVE-2026-39812 [MEDIUM] CWE-79 CVE-2026-39812: A improper neutralization of input during web page generation ('cross-site scripting') vulnerability
A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox PaaS 5.0.0 through 5.0.5, FortiSandbox PaaS 4.4.0 through 4.4.8, FortiSandbox PaaS 4.2 all versions may allow attacker to execu
nvd
CVE-2026-27316P4LOWCVSS 2.7v5.0.4v5.0.52026-04-14
CVE-2026-27316 [LOW] CWE-522 CVE-2026-27316: A insufficiently protected credentials vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, F
A insufficiently protected credentials vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4 all versions, FortiSandbox PaaS 5.0.1 through 5.0.5 may allow an authenticathed administrator to read LDAP server credentials via client-side inspection.
nvd