CVE-2025-46215: Fortinet FortiSandbox

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

An Improper Isolation or Compartmentalization vulnerability [CWE-653] in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an unauthenticated attacker to evade the sandboxing scan via a crafted file.

Affected products

  • Fortinet FortiSandbox: from 4.0.0, before 4.4.8 (fixed in 4.4.8); from 5.0.0, before 5.0.2 (fixed in 5.0.2)

Published 2025-11-18. Last modified 2026-06-17.