Improper Access Control in Fortinet FortiSandbox Products
CVE-2026-26084
8.9HIGH
Key Information:
- Vendor
Fortinet
- Vendor
- CVE Published:
- 8 September 2026
What is CVE-2026-26084?
An improper access control issue has been identified in Fortinet's FortiSandbox, spanning multiple versions. This vulnerability allows attackers to manipulate crafted HTTP requests, potentially granting them unauthorized access to sensitive information stored within the affected FortiSandbox instances. Users are strongly encouraged to assess their configurations and apply necessary mitigations to safeguard their data against exploitation.
Affected Version(s)
FortiSandbox 5.0.0 <= 5.0.5
FortiSandbox 4.4.0 <= 4.4.8
FortiSandbox 4.2.1 <= 4.2.8