PT-2026-58073 · Fortinet · Fortisandbox
CVE-2026-59835
·
Published
2026-07-14
·
Updated
2026-07-16
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:N/C:C/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
FortiSandbox versions 5.0.0 through 5.0.2
FortiSandbox versions 4.4.3 through 4.4.8
Description
An exposure of resource to wrong sphere issue allows an unauthenticated attacker to access the VNC server of virtual machines performing malware scanning via crafted network requests. This flaw enables remote access to analysis sessions, screenshots, and security research activities without requiring credentials or user interaction, potentially exposing sensitive sandbox data and malware samples.
Recommendations
Upgrade FortiSandbox versions 5.0.0 through 5.0.2 to version 5.0.3 or later.
Upgrade FortiSandbox versions 4.4.3 through 4.4.8 to version 4.4.9 or later.
Fix
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortisandbox