Friday, September 11, 2026

Fortinet FortiSandbox Vulnerability Lets Attackers Execute Unauthorized Commands

Fortinet has disclosed a critical vulnerability in its FortiSandbox product that could allow attackers to execute unauthorized commands without authentication, raising significant concerns for enterprises that rely on sandboxing for malware analysis.

Tracked as CVE-2026-25089, the flaw is classified as an OS command injection vulnerability (CWE-78). It carries a CVSS v3 score of 9.1, indicating high severity. The issue stems from improper neutralization of special elements in operating system commands within the FortiSandbox web-based management interface.

Fortinet FortiSandbox Vulnerability

The vulnerability specifically affects the “start VNC” feature in the GUI, where specially crafted JSON input can trigger a second-order command injection. In this type of attack, malicious input is first stored or processed and later executed in a different context, making detection more difficult.

An unauthenticated attacker can exploit the flaw by sending crafted HTTP requests to the affected interface. Because no authentication is required, the attack surface is significantly broader, especially for internet-exposed systems.

Successful exploitation could allow attackers to execute arbitrary commands on the underlying system, potentially leading to full system compromise, data exfiltration, or lateral movement within the network.

Affected Versions

The vulnerability impacts the following versions:

  • FortiSandbox 5.0.0 through 5.0.5
  • FortiSandbox 4.4.0 through 4.4.8
  • FortiSandbox Cloud 5.0.4 through 5.0.5
  • FortiSandbox PaaS 5.0.4 through 5.0.5

Versions such as FortiSandbox 5.2, FortiSandbox Cloud 5.2, and FortiSandbox PaaS 23.4 are not affected.

Patches and Mitigation

Fortinet has released patches to address the issue and strongly recommends upgrading to the following versions:

  • FortiSandbox 5.0.6 or later
  • FortiSandbox 4.4.9 or later
  • FortiSandbox Cloud 5.0.6 or later
  • FortiSandbox PaaS 5.0.6 or later

There are currently no reports of active exploitation in the wild. However, given the critical severity and ease of exploitation, organizations are advised to apply updates immediately.

As a mitigation measure, administrators should restrict access to the FortiSandbox management interface, ensure it is not exposed to the public internet, and monitor logs for suspicious HTTP requests targeting the GUI.

The vulnerability was internally discovered and reported by Adham El Karn of Fortinet’s Product Security Incident Response Team (PSIRT). It was publicly disclosed on June 9, 2026, under advisory ID FG-IR-26-141.

Security teams should prioritize patching and review exposure of sandbox environments, as these systems often handle high-risk files and are attractive targets for attackers seeking initial access or privilege escalation within enterprise networks.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News