CVE-2026-84387

Summary

A improper neutralization of special elements used in a command ('command injection') vulnerability in Fortinet FortiSandbox 5.2.0, FortiSandbox 5.0.0 through 5.0.6, FortiSandbox 4.4.0 through 4.4.9 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

Affected Software

VendorProductVersion RangeStatus
FortinetFortiSandbox5.2.0affected
FortinetFortiSandbox5.0.0 <= 5.0.6affected
FortinetFortiSandbox4.4.0 <= 4.4.9affected
FortinetFortiSandbox4.2.1 <= 4.2.8affected

Weaknesses

  • CWE-77: Execute unauthorized code or commands

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References