Description
A improper neutralization of special elements used in a command ('command injection') vulnerability in Fortinet FortiSandbox 5.2.0, FortiSandbox 5.0.0 through 5.0.6, FortiSandbox 4.4.0 through 4.4.9 may allow attacker to execute unauthorized code or commands via <insert attack vector here>
Published: 2026-09-08
Score: 6.7 Medium
EPSS: 1.4% Low
KEV: No
Impact: Remote Command Execution
Action: Apply Patch
AI Analysis

Impact

A command injection weakness exists in Fortinet FortiSandbox due to improper neutralization of special elements used in a command. This flaw allows an attacker to inject and execute arbitrary system commands on the FortiSandbox host, potentially compromising the entire sandbox environment. The vulnerability is identified as CWE‑77 and could lead to loss of data confidentiality, integrity, and availability if exploited.

Affected Systems

The affected products are Fortinet FortiSandbox versions 5.2.0, 5.0.0 through 5.0.6, and 4.4.0 through 4.4.9. Any deployment using these legacy releases is susceptible unless upgraded to a supported version. The vendor provides separate patch release paths for the 5.x and 4.x branches, with the newest corrective releases being 5.2.1, 5.0.7, and 4.4.10 respectively.

Risk and Exploitability

The CVSS base score of 6.7 reflects moderate severity; EPSS information is unavailable, so actual exploitation likelihood is unknown. The flaw is not listed in the CISA KEV catalog, indicating no known widespread exploitation. The attack vector is not explicitly detailed in the advisory, but it is inferred that an attacker must be able to submit input that reaches the vulnerable command construction, such as uploading a malicious file or sending a crafted API request. Once achieved, the attacker can execute arbitrary commands with the privileges of the FortiSandbox service, posing a serious threat to systems that rely on sandbox isolation.

Generated by OpenCVE AI on September 8, 2026 at 18:01 UTC.

Remediation

Vendor Solution

Upgrade to FortiSandbox version 5.2.1 or above Upgrade to FortiSandbox version 5.0.7 or above Upgrade to upcoming FortiSandbox version 4.4.10 or above


OpenCVE Recommended Actions

  • Upgrade to FortiSandbox 5.2.1 or later, or 5.0.7 or later, or 4.4.10 or later, depending on the series in use.
  • Limit exposure of the FortiSandbox appliance to trusted networks and restrict unauthorized API and file‑upload access.
  • Enable comprehensive logging and monitor for unusual command execution patterns or repeated failed attempts in the sandbox environment.

Generated by OpenCVE AI on September 8, 2026 at 18:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Title Command Injection Vulnerability in FortiSandbox Enables Arbitrary Code Execution

Tue, 08 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description A improper neutralization of special elements used in a command ('command injection') vulnerability in Fortinet FortiSandbox 5.2.0, FortiSandbox 5.0.0 through 5.0.6, FortiSandbox 4.4.0 through 4.4.9 may allow attacker to execute unauthorized code or commands via <insert attack vector here>
First Time appeared Fortinet
Fortinet fortisandbox
Weaknesses CWE-77
CPEs cpe:2.3:a:fortinet:fortisandbox:4.2.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.2.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.2.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.2.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.2.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.2.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.2.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.2.8:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.4.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.4.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.4.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.4.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.4.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.4.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.4.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.4.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.4.8:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:4.4.9:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:5.0.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:5.0.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:5.0.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:5.0.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:5.0.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:5.2.0:*:*:*:*:*:*:*
Vendors & Products Fortinet
Fortinet fortisandbox
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C'}


Subscriptions

Fortinet Fortisandbox
cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published:

Updated: 2026-09-08T17:39:42.017Z

Reserved: 2026-09-01T16:36:07.654Z

Link: CVE-2026-84387

cve-icon Vulnrichment

Updated: 2026-09-08T17:39:37.219Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T17:18:37.290

Modified: 2026-09-08T18:35:10.323

Link: CVE-2026-84387

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T18:15:15Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')