Insufficiently Protected Credentials in Fortinet FortiSandbox Products
CVE-2026-27316

2.5LOW

Key Information:

Vendor

Fortinet

Vendor
CVE Published:
14 April 2026

What is CVE-2026-27316?

A vulnerability has been identified in Fortinet's FortiSandbox that could allow authenticated administrators to access sensitive LDAP server credentials through client-side inspection. This issue affects multiple versions of FortiSandbox, including 5.0.0 to 5.0.5 and all versions of 4.4, as well as FortiSandbox PaaS 5.0.1 to 5.0.5. The improper handling of credentials could lead to unauthorized access, highlighting the importance of implementing robust security measures to protect sensitive information.

Affected Version(s)

FortiSandbox 5.0.0 <= 5.0.5

FortiSandbox 4.4.0 <= 4.4.9

FortiSandbox PaaS 23.4.4374

References

CVSS V3.1

Score:
2.5
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.