Improper Access Control in Fortinet FortiSandbox Products
CVE-2026-26084

8.9HIGH

What is CVE-2026-26084?

CVE-2026-26084 is a significant vulnerability found in Fortinet's FortiSandbox products, specifically versions 5.0.0 to 5.0.5 and 4.4.0 to 4.4.8, as well as FortiSandbox Cloud and PaaS versions 5.0.4 to 5.0.5. FortiSandbox is a malware analysis solution that helps organizations detect and mitigate threats by isolating and executing suspicious files to observe their behavior in a controlled environment. The vulnerability stems from improper access control mechanisms, which could allow attackers to exploit crafted HTTP requests to gain unauthorized access to sensitive information. If exploited, this vulnerability poses a serious risk, as it could enable malicious actors to compromise the integrity and confidentiality of sensitive organizational data, potentially leading to broader security breaches.

Potential Impact of CVE-2026-26084

  1. Unauthorized Access to Sensitive Data: The flaw could allow attackers to obtain sensitive information that is otherwise protected, which may include customer data, intellectual property, or security configurations, thus jeopardizing data privacy and compliance.

  2. Increased Attack Surface: By exploiting this vulnerability, threat actors can expand their foothold within an organization’s network, potentially leading to further attacks, including data exfiltration or system manipulation, thereby increasing the overall risk to the organization.

  3. Loss of Trust and Reputation: A breach resulting from this vulnerability could severely impact an organization’s reputation, resulting in a loss of customer trust, potential legal repercussions, and financial losses associated with incident response and remediation efforts.

Affected Version(s)

FortiSandbox 5.0.0 <= 5.0.5

FortiSandbox 4.4.0 <= 4.4.8

FortiSandbox 4.2.1 <= 4.2.8

References

CVSS V3.1

Score:
8.9
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.