Path Traversal Vulnerability in Fortinet FortiSandbox Products
CVE-2026-39813

9.1CRITICAL

Key Information:

Vendor

Fortinet

Vendor
CVE Published:
14 April 2026

Badges

📈 Score: 434👾 Exploit Exists🟡 Public PoC🟣 EPSS 16%📰 News Worthy

What is CVE-2026-39813?

CVE-2026-39813 is a path traversal vulnerability identified in Fortinet's FortiSandbox products, specifically affecting versions 5.0.0 to 5.0.5 and 4.4.0 to 4.4.8. FortiSandbox is designed to provide advanced threat protection through sandboxing technology, allowing organizations to examine and analyze potentially malicious files in a secure environment. This vulnerability arises from inadequate validation of user input, allowing attackers to manipulate file paths and access restricted directories. If exploited, this could lead to privilege escalation, enabling unauthorized users to gain access to sensitive data and system functionalities, posing significant security risks to organizations relying on FortiSandbox for threat detection and prevention.

Potential impact of CVE-2026-39813

  1. Privilege Escalation: The vulnerability allows attackers to escalate their privileges, potentially granting them unauthorized access to sensitive files and administrative capabilities within FortiSandbox. This could compromise the security integrity of the entire system.

  2. Data Breach Risks: Exploiting this vulnerability may enable attackers to access and exfiltrate confidential data stored within the FortiSandbox environment, leading to potential data breaches and exposing organizations to legal and reputational repercussions.

  3. Increased Attack Surface: The existence of this vulnerability can make affected systems more attractive targets for cybercriminals, especially since FortiSandbox is utilized for security operations. This could lead to further exploitation of the system and allow attackers to deploy additional malicious activities or malware within the network.

Affected Version(s)

FortiSandbox 5.0.0 <= 5.0.5

FortiSandbox 4.4.0 <= 4.4.8

FortiSandbox Cloud 24.1

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker Crosshairs

Fortinet FortiSandbox vulnerabilities tracked as CVE-2026-39808, CVE-2026-39813, and CVE-2026-25089 are being targeted in the wild.

2 weeks ago

Attackers are exploiting FortiSandbox vulnerabilities - IT Security News

Attackers have been spotted exploiting three vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) in FortiSandbox, a platform that other Fortinet security products depend on for threat verdicts to enforce blocking decisions and trigger automated responses. The warning came on Monday from...

2 weeks ago

Attackers are exploiting FortiSandbox vulnerabilities - Help Net Security

Attackers have been spotted exploiting three vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) in FortiSandbox.

2 weeks ago

References

EPSS Score

16% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • 📰

    First article discovered by Plato Data Intelligence

  • Vulnerability published

  • Vulnerability Reserved

.