Description
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests
Published: 2026-06-09
Score: 9.1 Critical
EPSS: 73.6% High
KEV: Yes
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an OS command injection that allows an unauthenticated attacker to execute arbitrary operating system commands on a FortiSandbox system. The flaw arises from improper neutralization of special elements used in an operating system command and is classified as CWE‑78. An attacker can craft specially designed HTTP requests to trigger the injection and gain full control of the underlying host, compromising confidentiality, integrity, and availability.

Affected Systems

Fortinet FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS are affected. Any instance running FortiSandbox version 5.0.0 through 5.0.5, 4.4.0 through 4.4.8, or any 4.2.x release is vulnerable. FortiSandbox Cloud is vulnerable for versions 5.0.4 through 5.0.5, and FortiSandbox PaaS for versions 5.0.4 through 5.0.5.

Risk and Exploitability

The EPSS score of 74% indicates a high probability of exploitation in the wild, while the CVSS score of 9.1 reflects a very high severity impact. The flaw permits an unauthenticated attacker to execute arbitrary OS commands via specially crafted HTTP requests, granting full remote code execution. FortiSandbox Cloud does not require action now because Fortinet has remediated the issue in forthcoming releases; plan to upgrade once 5.0.6 becomes available. It has been added to CISA’s KEV catalog, underscoring the urgency due to the high CVSS score and the elevated EPSS.

Generated by OpenCVE AI on August 6, 2026 at 14:46 UTC.

Remediation

Vendor Solution

Upgrade to upcoming FortiSandbox version 5.2.0 or above Upgrade to FortiSandbox version 5.0.6 or above Upgrade to FortiSandbox version 4.4.9 or above Upgrade to upcoming FortiSandbox PaaS version 5.2.0 or above Upgrade to FortiSandbox PaaS version 5.0.6 or above Fortinet remediated this issue in FortiSandbox Cloud version 5.2.0 (not released) and hence customers do not need to perform any action. Fortinet remediated this issue in FortiSandbox Cloud version 5.0.6 (not released) and hence customers do not need to perform any action.


OpenCVE Recommended Actions

  • Upgrade on‑prem FortiSandbox to version 5.0.6 or above. This upgrade path includes the upcoming 5.2.0 release and all subsequent patches.
  • If running an older FortiSandbox release (4.4.x series), upgrade to version 4.4.9 or above to obtain the fix.
  • For FortiSandbox PaaS deployments, upgrade to version 5.0.6 or above. This covers the forthcoming 5.2.0 which is not yet released.
  • FortiSandbox Cloud users do not need to act now because Fortinet has remediated the issue in upcoming, not yet released versions 5.0.6 and 5.2.0; plan to upgrade when those releases become available.
  • Optionally, restrict or monitor traffic to FortiSandbox API endpoints until a patch is applied.

Generated by OpenCVE AI on August 6, 2026 at 14:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Fortinet FortiSandbox Versions 4.2‑5.0, Cloud, and PaaS

Sun, 02 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Fortinet FortiSandbox Versions 4.2‑5.0, Cloud, and PaaS

Mon, 27 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title FortiSandbox OS Command Injection Vulnerability

Thu, 16 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2026-07-16T00:00:00+00:00', 'dueDate': '2026-07-19T00:00:00+00:00'}


Wed, 24 Jun 2026 13:30:00 +0000

Type Values Removed Values Added
Title FortiSandbox OS Command Injection Vulnerability

Wed, 24 Jun 2026 10:00:00 +0000

Type Values Removed Values Added
Title FortiSandbox OS Command Injection Vulnerability

Wed, 24 Jun 2026 05:30:00 +0000

Type Values Removed Values Added
Title FortiSandbox OS Command Injection Vulnerability

Wed, 24 Jun 2026 02:15:00 +0000

Type Values Removed Values Added
Title FortiSandbox OS Command Injection Enables Unauthenticated Remote Code Execution

Tue, 23 Jun 2026 23:00:00 +0000

Type Values Removed Values Added
Title FortiSandbox OS Command Injection Enables Unauthenticated Remote Code Execution

Tue, 23 Jun 2026 18:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated OS Command Injection Enables Remote Execution in FortiSandbox

Tue, 23 Jun 2026 15:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated OS Command Injection Enables Remote Execution in FortiSandbox

Wed, 17 Jun 2026 05:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated OS Command Injection in FortiSandbox via HTTP Requests

Tue, 16 Jun 2026 12:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated OS Command Injection in FortiSandbox via HTTP Requests

Thu, 11 Jun 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Fortinet fortisandbox Cloud
Fortinet fortisandbox Paas
CPEs cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox_cloud:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox_paas:*:*:*:*:*:*:*:*
Vendors & Products Fortinet fortisandbox Cloud
Fortinet fortisandbox Paas

Wed, 10 Jun 2026 16:00:00 +0000

Type Values Removed Values Added
Title Unrestricted OS Command Injection in Fortinet FortiSandbox

Wed, 10 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 10 Jun 2026 06:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 17:15:00 +0000

Type Values Removed Values Added
Title Unrestricted OS Command Injection in Fortinet FortiSandbox

Tue, 09 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Description A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests
First Time appeared Fortinet
Fortinet fortisandbox
Fortinet fortisandboxcloud
Fortinet fortisandboxpaas
Weaknesses CWE-78
CPEs cpe:2.3:a:fortinet:fortisandbox:4.2.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.2.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.2.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.2.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.2.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.2.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.2.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.2.8:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.4.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.4.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.4.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.4.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.4.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.4.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.4.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.4.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.4.8:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:5.0.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:5.0.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:5.0.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:5.0.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandboxcloud:5.0.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandboxcloud:5.0.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandboxpaas:5.0.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandboxpaas:5.0.5:*:*:*:*:*:*:*
Vendors & Products Fortinet
Fortinet fortisandbox
Fortinet fortisandboxcloud
Fortinet fortisandboxpaas
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C'}


Subscriptions

Fortinet Fortisandbox Fortisandbox Cloud Fortisandbox Paas Fortisandboxcloud Fortisandboxpaas
cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published:

Updated: 2026-07-17T03:56:23.142Z

Reserved: 2026-01-29T09:27:29.820Z

Link: CVE-2026-25089

cve-icon Vulnrichment

Updated: 2026-06-09T15:36:07.778Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-09T16:16:39.943

Modified: 2026-07-23T08:10:00.137

Link: CVE-2026-25089

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T15:00:11Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')