Path Traversal Vulnerability in Fortinet FortiSandbox Products
CVE-2026-39813
Key Information:
- Vendor
Fortinet
- Vendor
- CVE Published:
- 14 April 2026
Badges
What is CVE-2026-39813?
CVE-2026-39813 is a path traversal vulnerability identified in Fortinet's FortiSandbox products, specifically affecting versions 5.0.0 to 5.0.5 and 4.4.0 to 4.4.8. FortiSandbox is designed to provide advanced threat protection through sandboxing technology, allowing organizations to examine and analyze potentially malicious files in a secure environment. This vulnerability arises from inadequate validation of user input, allowing attackers to manipulate file paths and access restricted directories. If exploited, this could lead to privilege escalation, enabling unauthorized users to gain access to sensitive data and system functionalities, posing significant security risks to organizations relying on FortiSandbox for threat detection and prevention.
Potential impact of CVE-2026-39813
-
Privilege Escalation: The vulnerability allows attackers to escalate their privileges, potentially granting them unauthorized access to sensitive files and administrative capabilities within FortiSandbox. This could compromise the security integrity of the entire system.
-
Data Breach Risks: Exploiting this vulnerability may enable attackers to access and exfiltrate confidential data stored within the FortiSandbox environment, leading to potential data breaches and exposing organizations to legal and reputational repercussions.
-
Increased Attack Surface: The existence of this vulnerability can make affected systems more attractive targets for cybercriminals, especially since FortiSandbox is utilized for security operations. This could lead to further exploitation of the system and allow attackers to deploy additional malicious activities or malware within the network.
Affected Version(s)
FortiSandbox 5.0.0 <= 5.0.5
FortiSandbox 4.4.0 <= 4.4.8
FortiSandbox Cloud 24.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker Crosshairs
Fortinet FortiSandbox vulnerabilities tracked as CVE-2026-39808, CVE-2026-39813, and CVE-2026-25089 are being targeted in the wild.
2 weeks ago
Attackers are exploiting FortiSandbox vulnerabilities - IT Security News
Attackers have been spotted exploiting three vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) in FortiSandbox, a platform that other Fortinet security products depend on for threat verdicts to enforce blocking decisions and trigger automated responses. The warning came on Monday from...
2 weeks ago
Attackers are exploiting FortiSandbox vulnerabilities - Help Net Security
Attackers have been spotted exploiting three vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) in FortiSandbox.
2 weeks ago
References
EPSS Score
16% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
- 📰
First article discovered by Plato Data Intelligence
Vulnerability published
Vulnerability Reserved