Description
A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests.
Published: 2026-07-14
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Fortinet FortiSandbox versions 4.4.3 through 4.4.8 and 5.0.0 through 5.0.2 contain a misconfiguration that exposes the VNC service of sandbox virtual machines to unauthenticated network requests. This flaw allows an attacker to connect to the VNC session and view or control the sandbox VM, providing access to the internal sandbox environment without needing credentials. The vulnerability is an instance of CWE‑668, improper access control of resources.

Affected Systems

Affected vendor: Fortinet. Product: FortiSandbox. Affected versions: 4.4.3‑4.4.8 and 5.0.0‑5.0.2.

Risk and Exploitability

The CVSS score is 7.7, indicating high severity, while the EPSS score is under 1 % and the vulnerability is not listed in CISA’s KEV catalog, suggesting that exploitation is unlikely to be widespread at present. An attacker can exploit the flaw from any network‑connected system by sending unauthenticated requests to the exposed VNC port, and the attack can be performed over the network with no authentication required.

Generated by OpenCVE AI on August 1, 2026 at 09:59 UTC.

Remediation

Vendor Solution

Upgrade to FortiSandbox version 5.0.3 or above Upgrade to FortiSandbox version 4.4.9 or above


OpenCVE Recommended Actions

  • Upgrade FortiSandbox to version 5.0.3 or newer, or to 4.4.9 or newer if using earlier releases.
  • Disable or restrict external VNC access on sandbox VMs until the upgrade is complete.
  • Apply network segmentation or firewall rules to block unauthenticated traffic to the VNC port from untrusted networks.

Generated by OpenCVE AI on August 1, 2026 at 09:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated VNC Access in FortiSandbox Allowing Remote Desktop

Wed, 29 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated VNC Access in FortiSandbox Allowing Remote Desktop

Sun, 26 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated VNC Access in FortiSandbox

Thu, 23 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated VNC Access in FortiSandbox

Mon, 20 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated VNC Server Access via Resource Exposure in FortiSandbox

Thu, 16 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated VNC Server Access via Resource Exposure in FortiSandbox

Tue, 14 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests.
First Time appeared Fortinet
Fortinet fortisandbox
Weaknesses CWE-668
CPEs cpe:2.3:a:fortinet:fortisandbox:4.4.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.4.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.4.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.4.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.4.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.4.8:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:5.0.2:*:*:*:*:*:*:*
Vendors & Products Fortinet
Fortinet fortisandbox
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L/E:P/RL:O/RC:C'}


Subscriptions

Fortinet Fortisandbox
cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published:

Updated: 2026-07-16T07:35:10.603Z

Reserved: 2026-07-07T15:21:25.057Z

Link: CVE-2026-59835

cve-icon Vulnrichment

Updated: 2026-07-14T15:55:20.974Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:00:04Z

Weaknesses
  • CWE-668

    Exposure of Resource to Wrong Sphere