Tuesday, September 29, 2026

Fortinet FortiSandbox Vulnerability Allows Unauthenticated Attackers to Access Sensitive Information

Fortinet has disclosed a critical vulnerability involving improper access control in the FortiSandbox web interfaces. This issue could allow an unauthenticated remote attacker to access sensitive information by sending specially crafted HTTP requests.

The vulnerability is tracked as CVE-2026-26084 and documented in advisory FG-IR-26-166. It affects the graphical user interface (GUI) component of FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS.

Fortinet has assigned a CVSS v3.1 score of 8.9 to this vulnerability, indicating high severity due to factors such as network reachability, low attack complexity, the absence of required privileges or user interaction, and potential impacts on confidentiality, integrity, and availability.

Fortinet FortiSandbox Vulnerability

The issue is classified under CWE-284, which pertains to Improper Access Control. Fortinet describes the vulnerability as “unauthenticated control of NAT rules leading to the exposure of sensitive information.”

In practical terms, this means that vulnerable devices may fail to correctly enforce authorization checks for a web interface function related to Network Address Translation (NAT) rules.

A remote attacker who can access the management interface could submit specially formatted HTTP requests without prior authentication. Fortinet’s advisory does not specify the exact request format, the records exposed, or provide a proof of concept, so defenders should not assume only low-value configuration data is at risk.

The vulnerable versions include FortiSandbox 5.0.0 to 5.0.5 and FortiSandbox 4.4.0 to 4.4.8. Additionally, FortiSandbox Cloud versions 5.0.4 to 5.0.5 and FortiSandbox PaaS versions 5.0.4 to 5.0.5 are also affected.

Organizations using the impacted 5.0 product line should upgrade to version 5.0.6 or later, while those on the 4.4 branch must move to version 4.4.9 or later. Fortinet notes that FortiSandbox 5.2, FortiSandbox Cloud 4.4, and FortiSandbox PaaS 5.2 are not affected by this vulnerability.

Because exploitation does not require credentials, exposure of the administrative GUI significantly increases risk. Security teams should promptly identify FortiSandbox instances, including hosted Cloud and PaaS deployments, confirm their running versions, and prioritize remediation for interfaces accessible from the internet or less-trusted network segments.

Until patching is complete, administrators should restrict GUI access to dedicated management networks, enforce allowlisting through firewalls or VPN gateways, and review reverse-proxy and NAT configurations that might unintentionally expose the service.

Teams should also analyze web-server, application, and perimeter logs for any unusual requests targeting FortiSandbox management paths, particularly those from unfamiliar sources, repeated malformed HTTP parameters, and unexpected changes to NAT configurations.

Any suspected compromise should trigger a review of appliance settings, privileged accounts, connected network paths, and potentially exposed information. Fortinet reports that Adham El Karn of its Product Security team discovered the vulnerability internally, and there have been no known exploitations as of the advisory’s publication on September 8.

Fortinet’s Product Security Incident Response Team (PSIRT) manages the reporting and resolution of vulnerabilities. Organizations should retain relevant logs before performing upgrades, document exposed management endpoints, and ensure that compensating controls do not interfere with sandbox submissions, analyses, or operations during remediation.

The lack of public exploitation should not delay remediation efforts, as pre-authentication flaws in security management interfaces may become attractive targets once technical details are disclosed.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection. 

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

DPRK-Linked Hackers Add HashHiding to Blockchain C2 Network for Takedown-Resistant Malware

DPRK-linked operators behind the Cross-Chain TxDataHiding (XCTDH) campaign have...

Critical WatchGuard AP Flaws Let Unauthenticated Attackers Execute Arbitrary Commands

WatchGuard has announced the discovery of three high-impact vulnerabilities...

SilverFox Built Fake Software Sites That Know When Researchers Are Watching

SilverFox-linked operators are evolving beyond counterfeit software portals and...

Apple Fixes iOS Zero-Day Exploited in Sophisticated Targeted Attacks

Apple has released iOS 26.7.1 and iPadOS 26.7.1 to...

Attackers Hid Behind Trusted RMM Software Before Deploying a Full Surveillance RAT

Threat actors are abusing trusted remote monitoring and management...

Keio Railway Confirms Ransomware Attack Disrupted Business Systems

Keio Corporation has confirmed that a ransomware attack has...

Microsoft Tracks NeedyMantis Malware Targeting Telecoms and Government Contractors

Microsoft Threat Intelligence has discovered NeedyMantis, a modular post-compromise...

Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials

Microsoft has uncovered an Azure-focused destructive campaign linked to...

Related Articles

Recent News