Cross-Site Scripting Vulnerability in Fortinet FortiSandbox Products
CVE-2026-39812
4.3MEDIUM
What is CVE-2026-39812?
An improper neutralization of input during web page generation in Fortinet FortiSandbox allows an attacker to execute unauthorized code or commands. This vulnerability affects multiple versions of FortiSandbox and FortiSandbox PaaS, enabling potential exploitation through crafted web input that could lead to unauthorized command execution.
Affected Version(s)
FortiSandbox 5.0.0 <= 5.0.4
FortiSandbox 4.4.0 <= 4.4.8
FortiSandbox 4.2.1 <= 4.2.8