Description
A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially crafted HTTP requests.
Published: 2026-04-14
Score: 9.1 Critical
EPSS: 23.1% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A directory traversal flaw, identified as CWE-24, exists in Fortinet FortiSandbox versions 4.4.0 through 4.4.8 and 5.0.0 through 5.0.5. When an attacker sends a crafted HTTP request containing the sequence '../filedir', the sandbox may resolve paths outside the intended sandbox directory, allowing the attacker to access files or execute code with the privileges of the sandbox host. As a result, the attacker can elevate their privileges on the FortiSandbox system without authentication. This flaw directly violates the principle of least privilege and enables unauthorized modification of system files or execution of arbitrary code.

Affected Systems

FortiSandbox on-premises installations feature versions 4.4.0 to 4.4.8 and 5.0.0 to 5.0.5, while the FortiSandbox Cloud service offers versions 23.4, 24.1, 5.0.4, and 5.0.5. All affected instances expose an HTTP interface that can be remotely accessed by network users, making them susceptible to this traversal attack regardless of location.

Risk and Exploitability

The base CVSS score of 9.1 classifies the vulnerability as critical. An EPSS score of 23% indicates a moderate probability that attackers will target and exploit this flaw, even though it does not appear in the CISA KEV catalog. The attack vector is network‑based, requiring the ability to send HTTP requests to the FortiSandbox service. If an attacker succeeds, they can gain elevated privileges on the host machine, potentially compromising the entire infrastructure.

Generated by OpenCVE AI on August 4, 2026 at 08:44 UTC.

Remediation

Vendor Solution

Upgrade to upcoming FortiSandbox version 5.2.0 or above Upgrade to FortiSandbox version 5.0.6 or above Upgrade to FortiSandbox version 4.4.9 or above


OpenCVE Recommended Actions

  • Upgrade to FortiSandbox 5.2.0 or any later supported release to remove the directory traversal flaw.
  • If a 5.2.0 upgrade is not immediately possible, upgrade to the earliest fixed release such as FortiSandbox 5.0.6 or FortiSandbox 4.4.9.
  • Restrict access to the FortiSandbox HTTP interface by applying network segmentation, firewall rules, or authentication controls to limit the exposure of the vulnerable endpoints to trusted administrators only.

Generated by OpenCVE AI on August 4, 2026 at 08:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
Title Directory Traversal Allowing Privilege Escalation in Fortinet FortiSandbox

Thu, 30 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Directory Traversal Allowing Privilege Escalation in Fortinet FortiSandbox

Wed, 24 Jun 2026 10:00:00 +0000

Type Values Removed Values Added
Title Directory Traversal Leading to Privilege Escalation in FortiSandbox

Wed, 24 Jun 2026 06:00:00 +0000

Type Values Removed Values Added
Title Directory Traversal Leading to Privilege Escalation in FortiSandbox

Wed, 24 Jun 2026 03:45:00 +0000

Type Values Removed Values Added
Title Path Traversal Allowing Privilege Escalation via Specially Crafted HTTP Requests in FortiSandbox

Wed, 24 Jun 2026 00:00:00 +0000

Type Values Removed Values Added
Title Path Traversal Allowing Privilege Escalation via Specially Crafted HTTP Requests in FortiSandbox

Tue, 23 Jun 2026 17:00:00 +0000

Type Values Removed Values Added
Title FortiSandbox Path Traversal Enables Privilege Escalation via HTTP Requests

Thu, 18 Jun 2026 19:15:00 +0000

Type Values Removed Values Added
Title FortiSandbox Path Traversal Enables Privilege Escalation via HTTP Requests

Thu, 18 Jun 2026 16:45:00 +0000

Type Values Removed Values Added
Description A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via <insert attack vector here> A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially crafted HTTP requests.
Title Path Traversal Exploitation Allowing Privilege Escalation in Fortinet FortiSandbox

Wed, 17 Jun 2026 11:30:00 +0000

Type Values Removed Values Added
Title Path Traversal Exploitation Allowing Privilege Escalation in Fortinet FortiSandbox

Tue, 16 Jun 2026 14:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Path Traversal in FortiSandbox

Mon, 20 Apr 2026 19:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*

Wed, 15 Apr 2026 15:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Path Traversal in FortiSandbox

Tue, 14 Apr 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Apr 2026 16:00:00 +0000

Type Values Removed Values Added
Description A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via <insert attack vector here>
First Time appeared Fortinet
Fortinet fortisandbox
Fortinet fortisandboxcloud
Weaknesses CWE-24
CPEs cpe:2.3:a:fortinet:fortisandbox:4.4.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.4.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.4.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.4.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.4.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.4.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.4.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.4.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.4.8:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:5.0.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:5.0.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:5.0.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:5.0.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandboxcloud:23.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandboxcloud:24.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandboxcloud:5.0.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandboxcloud:5.0.5:*:*:*:*:*:*:*
Vendors & Products Fortinet
Fortinet fortisandbox
Fortinet fortisandboxcloud
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C'}


Subscriptions

Fortinet Fortisandbox Fortisandboxcloud
cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published:

Updated: 2026-06-18T09:01:15.877Z

Reserved: 2026-04-07T15:24:13.846Z

Link: CVE-2026-39813

cve-icon Vulnrichment

Updated: 2026-04-14T16:36:55.508Z

cve-icon NVD

Status : Modified

Published: 2026-04-14T16:16:45.680

Modified: 2026-06-18T13:25:36.770

Link: CVE-2026-39813

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T08:45:06Z

Weaknesses
  • CWE-24

    Path Traversal: '../filedir'