CVE-2026-26084

Summary

A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests.

Affected Software

VendorProductVersion RangeStatus
FortinetFortiSandbox PaaS5.0.4 <= 5.0.5affected
FortinetFortiSandbox5.0.0 <= 5.0.5affected
FortinetFortiSandbox4.4.0 <= 4.4.8affected
FortinetFortiSandbox4.2.1 <= 4.2.8affected
FortinetFortiSandbox Cloud5.0.4 <= 5.0.5affected

Weaknesses

  • CWE-284: Improper access control

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References