CVE-2026-26083

EUVD-2026-29550
A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 through 5.0.5, FortiSandbox PaaS 23.4 all versions, FortiSandbox PaaS 23.3 all versions, FortiSandbox PaaS 23.1 all versions, FortiSandbox PaaS 22.2 all versions, FortiSandbox PaaS 22.1 all versions, FortiSandbox PaaS 21.4 all versions, FortiSandbox PaaS 21.3 all versions, FortiSandbox PaaS 5.0.0 through 5.0.1, FortiSandbox PaaS 4.4.5 through 4.4.8 may allow an unauthenticated attacker to execute unauthorized code or commands via HTTP requests.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 49%
Affected Products (NVD)
VendorProductVersion
fortinetfortisandbox
4.4.0 ≤
𝑥
< 4.4.9
fortinetfortisandbox
5.0.0 ≤
𝑥
< 5.0.2
fortinetfortisandbox_cloud
5.0.2 ≤
𝑥
< 5.0.6
fortinetfortisandbox_cloud
23.1.4245 ≤
𝑥
≤ 23.4.4374
fortinetfortisandbox_cloud
24.1.4436
fortinetfortisandbox_paas
4.4.5 ≤
𝑥
< 4.4.9
fortinetfortisandbox_paas
5.0.0 ≤
𝑥
< 5.0.2
fortinetfortisandbox_paas
21.3.4055 ≤
𝑥
≤ 23.4.4374
𝑥
= Vulnerable software versions