PT-2026-47809 · Fortinet · Fortisandbox+2
CVE-2026-25089
·
Published
2026-06-09
·
Updated
2026-07-23
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
FortiSandbox versions 5.0.0 through 5.0.5
FortiSandbox versions 4.4.0 through 4.4.8
FortiSandbox version 4.2
FortiSandbox Cloud versions 5.0.4 through 5.0.5
FortiSandbox PaaS versions 5.0.4 through 5.0.5
Description
An OS command injection issue exists due to improper neutralization of special elements used in an OS command. This allows an unauthenticated remote attacker to execute unauthorized system commands by sending specifically crafted HTTP requests to the graphical user interface. OS command injection is a flaw where an application fails to properly sanitize input, allowing an attacker to execute arbitrary operating system commands on the server.
Recommendations
Upgrade FortiSandbox versions 5.0.0 through 5.0.5 to the vendor-fixed release.
Upgrade FortiSandbox versions 4.4.0 through 4.4.8 to the vendor-fixed release.
Upgrade FortiSandbox version 4.2 to the vendor-fixed release.
Upgrade FortiSandbox Cloud versions 5.0.4 through 5.0.5 to the vendor-fixed release.
Upgrade FortiSandbox PaaS versions 5.0.4 through 5.0.5 to the vendor-fixed release.
Restrict management interfaces to trusted administrative networks only.
Avoid exposing management interfaces directly to the Internet.
Review HTTP and system logs for unusual requests or command execution activity.
Monitor EDR/SIEM for abnormal outbound connections originating from the appliance.
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortisandbox
Fortisandbox Cloud
Fortisandbox Paas