PT-2026-47809 · Fortinet · Fortisandbox+2

CVE-2026-25089

·

Published

2026-06-09

·

Updated

2026-07-23

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FortiSandbox versions 5.0.0 through 5.0.5 FortiSandbox versions 4.4.0 through 4.4.8 FortiSandbox version 4.2 FortiSandbox Cloud versions 5.0.4 through 5.0.5 FortiSandbox PaaS versions 5.0.4 through 5.0.5
Description An OS command injection issue exists due to improper neutralization of special elements used in an OS command. This allows an unauthenticated remote attacker to execute unauthorized system commands by sending specifically crafted HTTP requests to the graphical user interface. OS command injection is a flaw where an application fails to properly sanitize input, allowing an attacker to execute arbitrary operating system commands on the server.
Recommendations Upgrade FortiSandbox versions 5.0.0 through 5.0.5 to the vendor-fixed release. Upgrade FortiSandbox versions 4.4.0 through 4.4.8 to the vendor-fixed release. Upgrade FortiSandbox version 4.2 to the vendor-fixed release. Upgrade FortiSandbox Cloud versions 5.0.4 through 5.0.5 to the vendor-fixed release. Upgrade FortiSandbox PaaS versions 5.0.4 through 5.0.5 to the vendor-fixed release. Restrict management interfaces to trusted administrative networks only. Avoid exposing management interfaces directly to the Internet. Review HTTP and system logs for unusual requests or command execution activity. Monitor EDR/SIEM for abnormal outbound connections originating from the appliance.

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08316
CVE-2026-25089

Affected Products

Fortisandbox
Fortisandbox Cloud
Fortisandbox Paas