CVE-2026-84387
6.7
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
Summary
A improper neutralization of special elements used in a command ('command injection') vulnerability in Fortinet FortiSandbox 5.2.0, FortiSandbox 5.0.0 through 5.0.6, FortiSandbox 4.4.0 through 4.4.9 may allow attacker to execute unauthorized code or commands via <insert attack vector here>
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Fortinet | FortiSandbox | 5.2.0 | affected |
| Fortinet | FortiSandbox | 5.0.0 <= 5.0.6 | affected |
| Fortinet | FortiSandbox | 4.4.0 <= 4.4.9 | affected |
| Fortinet | FortiSandbox | 4.2.1 <= 4.2.8 | affected |
Weaknesses
- CWE-77: Execute unauthorized code or commands
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.