VULNERABILITY OVERVIEW
A second OS command injection vulnerability (CWE-78) in the FortiSandbox web UI, targeting the VNC session initiation feature, allows unauthenticated attackers to execute unauthorized commands via crafted HTTP requests. Active exploitation confirmed since mid-June 2026 and added to CISA KEV on July 16, 2026. The vulnerability can be chained with CVE-2026-39813 (path traversal/auth bypass) and CVE-2026-39808 in a two-step HTTP sequence to achieve unauthenticated root access on the appliance — the device intended to safely analyze malware for the enterprise.
CVSS BREAKDOWN
↗
Attack Vector
NETWORK
△
Attack Complexity
LOW
⚷
Privs Required
NONE
◈
User Interaction
NONE
⊕
Scope / Impact
UNCHANGED
C:H · I:H · A:H
AFFECTED VERSIONS
FortiSandbox 4.2.x (all versions), 4.4.0–4.4.8, 5.0.0–5.0.5; FortiSandbox Cloud 5.0.4–5.0.5; FortiSandbox PaaS 5.0.4–5.0.5; fixed in 4.4.9+ and 5.0.6+CITATIONS
- → https://hellorecon.com/blog/cve-2026-25089
- → https://sanjayseth.com/fortisandbox-cve-2026-25089-39808-39813-exploit-chain
- → https://threatprotect.qualys.com/2026/06/17/fortinet-fortisandbox-vulnerability-exploited-by-attackers-cve-2026-39808-cve-2026-25089-cve-2026-39813/
- → https://www.cisa.gov/news-events/alerts/2026/07/16/cisa-adds-three-known-exploited-vulnerabilities-catalog