CVE-2026-26084: Fortinet FortiSandbox
Critical severity, CVSS 9.9. EPSS: 0.4% chance of exploitation in the next 30 days.
A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests.
Affected products
- Fortinet FortiSandbox: from 5.0.0, up to and including 5.0.5; from 4.4.0, up to and including 4.4.8; from 4.2.1, up to and including 4.2.8
- Fortinet FortiSandbox Cloud: from 5.0.4, up to and including 5.0.5
- Fortinet FortiSandbox Paas: from 5.0.4, up to and including 5.0.5
Published 2026-09-08. Last modified 2026-09-08.