VULNERABILITY OVERVIEW
An improper neutralization of special elements in OS commands (CWE-78) at the /fortisandbox/job-detail/tracer-behavior endpoint allows unauthenticated attackers to inject shell metacharacters via the jid parameter, executing commands with system-level privileges. CrowdSec detected 49 unique malicious IPs in the early exploitation phase, with first in-the-wild exploitation observed June 17, 2026. Public PoC exploit code and a Nuclei detection template are available on GitHub. CISA added to KEV July 16, 2026; security researchers demonstrated chaining with CVE-2026-39813 for unauthenticated root access.
CVSS BREAKDOWN
↗
Attack Vector
NETWORK
△
Attack Complexity
LOW
⚷
Privs Required
NONE
◈
User Interaction
NONE
⊕
Scope / Impact
UNCHANGED
C:H · I:H · A:H
AFFECTED VERSIONS
FortiSandbox 4.4.0 through 4.4.8; FortiSandbox PaaS (prior to 5.0.6); fixed in 4.4.9+ and 5.0.6+CITATIONS
- → https://arcticwolf.com/resources/blog/cve-2026-39808/
- → https://www.crowdsec.net/vulntracking-report/cve-2026-39808-fortinet-fortisandbox-command-injection
- → https://threatprotect.qualys.com/2026/06/17/fortinet-fortisandbox-vulnerability-exploited-by-attackers-cve-2026-39808-cve-2026-25089-cve-2026-39813/
- → https://www.cisa.gov/news-events/alerts/2026/07/16/cisa-adds-three-known-exploited-vulnerabilities-catalog