CVE-2024-52960: Fortinet FortiSandbox

High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.

A client-side enforcement of server-side security vulnerability [CWE-602] in Fortinet FortiSandbox version 5.0.0, 4.4.0 through 4.4.6 and before 4.2.7 allows an authenticated attacker with at least read-only permission to execute unauthorized commands via crafted requests.

Affected products

  • Fortinet FortiSandbox: from 3.0.0, before 4.2.8 (fixed in 4.2.8); from 4.4.0, before 4.4.7 (fixed in 4.4.7); version 5.0.0 only

Published 2025-03-11. Last modified 2026-06-17.