Fortinet has disclosed a critical vulnerability involving improper access control in the FortiSandbox web interfaces. This issue could allow an unauthenticated remote attacker to access sensitive information by sending specially crafted HTTP requests.
The vulnerability is tracked as CVE-2026-26084 and documented in advisory FG-IR-26-166. It affects the graphical user interface (GUI) component of FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS.
Fortinet has assigned a CVSS v3.1 score of 8.9 to this vulnerability, indicating high severity due to factors such as network reachability, low attack complexity, the absence of required privileges or user interaction, and potential impacts on confidentiality, integrity, and availability.
Fortinet FortiSandbox Vulnerability
The issue is classified under CWE-284, which pertains to Improper Access Control. Fortinet describes the vulnerability as “unauthenticated control of NAT rules leading to the exposure of sensitive information.”
In practical terms, this means that vulnerable devices may fail to correctly enforce authorization checks for a web interface function related to Network Address Translation (NAT) rules.
A remote attacker who can access the management interface could submit specially formatted HTTP requests without prior authentication. Fortinet’s advisory does not specify the exact request format, the records exposed, or provide a proof of concept, so defenders should not assume only low-value configuration data is at risk.
The vulnerable versions include FortiSandbox 5.0.0 to 5.0.5 and FortiSandbox 4.4.0 to 4.4.8. Additionally, FortiSandbox Cloud versions 5.0.4 to 5.0.5 and FortiSandbox PaaS versions 5.0.4 to 5.0.5 are also affected.
Organizations using the impacted 5.0 product line should upgrade to version 5.0.6 or later, while those on the 4.4 branch must move to version 4.4.9 or later. Fortinet notes that FortiSandbox 5.2, FortiSandbox Cloud 4.4, and FortiSandbox PaaS 5.2 are not affected by this vulnerability.
Because exploitation does not require credentials, exposure of the administrative GUI significantly increases risk. Security teams should promptly identify FortiSandbox instances, including hosted Cloud and PaaS deployments, confirm their running versions, and prioritize remediation for interfaces accessible from the internet or less-trusted network segments.
Until patching is complete, administrators should restrict GUI access to dedicated management networks, enforce allowlisting through firewalls or VPN gateways, and review reverse-proxy and NAT configurations that might unintentionally expose the service.
Teams should also analyze web-server, application, and perimeter logs for any unusual requests targeting FortiSandbox management paths, particularly those from unfamiliar sources, repeated malformed HTTP parameters, and unexpected changes to NAT configurations.
Any suspected compromise should trigger a review of appliance settings, privileged accounts, connected network paths, and potentially exposed information. Fortinet reports that Adham El Karn of its Product Security team discovered the vulnerability internally, and there have been no known exploitations as of the advisory’s publication on September 8.
Fortinet’s Product Security Incident Response Team (PSIRT) manages the reporting and resolution of vulnerabilities. Organizations should retain relevant logs before performing upgrades, document exposed management endpoints, and ensure that compensating controls do not interfere with sandbox submissions, analyses, or operations during remediation.
The lack of public exploitation should not delay remediation efforts, as pre-authentication flaws in security management interfaces may become attractive targets once technical details are disclosed.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.





