Command Injection Vulnerability in Fortinet FortiSandbox Products
CVE-2026-84387

6.7MEDIUM

Key Information:

Vendor

Fortinet

Vendor
CVE Published:
8 September 2026

What is CVE-2026-84387?

An improper neutralization of special elements used in commands has been identified in Fortinet's FortiSandbox products, potentially allowing an attacker to execute unauthorized code or commands through specially crafted input. This vulnerability is a serious concern as it can compromise the integrity and confidentiality of the system. Users are urged to apply patches and follow best security practices to mitigate risks associated with this flaw.

Affected Version(s)

FortiSandbox 5.2.0

FortiSandbox 5.0.0 <= 5.0.6

FortiSandbox 4.4.0 <= 4.4.9

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.