CVE-2026-39812

EUVD-2026-22342
A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox PaaS 5.0.0 through 5.0.5, FortiSandbox PaaS 4.4.0 through 4.4.8, FortiSandbox PaaS 4.2 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.8 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 10%
Affected Products (NVD)
VendorProductVersion
fortinetfortisandbox
4.2.0 ≤
𝑥
≤ 4.2.8
fortinetfortisandbox
4.4.0 ≤
𝑥
< 4.4.9
fortinetfortisandbox
5.0.0 ≤
𝑥
< 5.0.6
fortinetfortisandbox_cloud
22.2.4134 ≤
𝑥
≤ 23.1.4260
fortinetfortisandbox_cloud
23.3.4329 ≤
𝑥
≤ 24.1.4436
fortinetfortisandbox_cloud
5.0.4
fortinetfortisandbox_cloud
5.0.5
𝑥
= Vulnerable software versions