CVE-2026-39812: Fortinet FortiSandbox

Medium severity, CVSS 4.8. EPSS: 0.2% chance of exploitation in the next 30 days.

A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox PaaS 5.0.0 through 5.0.5, FortiSandbox PaaS 4.4.0 through 4.4.8, FortiSandbox PaaS 4.2 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>

Affected products

  • Fortinet FortiSandbox: from 4.2.0, up to and including 4.2.8; from 4.4.0, before 4.4.9 (fixed in 4.4.9); from 5.0.0, before 5.0.6 (fixed in 5.0.6)
  • Fortinet FortiSandbox Cloud: from 22.2.4134, up to and including 23.1.4260; from 23.3.4329, up to and including 24.1.4436; version 5.0.4 only; version 5.0.5 only

Published 2026-04-14. Last modified 2026-06-17.