CyberSecurityNews

FortiSandbox Vulnerability Allows Attackers to Access Sensitive Information via Crafted HTTP Requests


Fortinet has disclosed a new high-severity vulnerability affecting its FortiSandbox platform, warning that unauthenticated attackers could exploit weaknesses in the product’s web interface to siphon off sensitive information without ever needing valid credentials.

The flaw, tracked as CVE-2026-26084, stems from improper access control in the graphical user interface component that FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS all share, and it has been assigned a CVSS v3.1 score of 8.9, placing it firmly in the high-severity category.

FortiSandbox is widely deployed across enterprise and government networks as an advanced threat detection appliance, using sandboxing techniques to analyze suspicious files and network traffic for zero-day malware and other advanced threats.

FortiSandbox Vulnerability Exposes Sensitive Information

According to Fortinet’s advisory, the vulnerability is classified under CWE-284, Improper Access Control. In practical terms, this means the WEB UI fails to properly verify whether a request originates from an authorized session before returning sensitive data.

An attacker who understands the structure of the application’s internal API endpoints can craft specially formed HTTP requests and send them directly to the FortiSandbox web interface, bypassing the authentication checks that would normally gate access to that information.

The advisory notes that exploitation requires no user interaction and no prior privileges, which is reflected in the CVSS vector’s designation of the attack as unauthenticated.

While the vulnerability does not grant an attacker the ability to modify data or execute code, the confidentiality impact is still significant enough to warrant urgent patching, since exposed information from a security appliance like FortiSandbox could include configuration details, logs, or other operational data that attackers could use to plan follow-on intrusions.

Fortinet credits Adham El Karn of its own Product Security team with discovering and reporting the issue internally, rather than through an external researcher or bug bounty submission.

The company has stated there is no evidence that the vulnerability has been exploited in the wild, and it carries an “Internal” discovery tag along with a “No” rating for known exploitation as of the publication date.

FortiSandbox 5.2 is not affected, giving administrators on the latest version extra time to manage it. However, FortiSandbox 5.0 versions from 5.0.0 through 5.0.5 are vulnerable, and Fortinet recommends upgrading to 5.0.6 or later to close the gap. Similarly, FortiSandbox 4.4 versions between 4.4.0 and 4.4.8 are exposed, with 4.4.9 or above serving as the fixed release.

The cloud and platform-as-a-service variants show a mixed picture. FortiSandbox Cloud 5.0 is affected in the 5.0.4 through 5.0.5 range, again requiring an upgrade to 5.0.6 or above, while FortiSandbox Cloud 4.4 escapes the issue entirely.

On the PaaS side, FortiSandbox PaaS 5.2 is unaffected, but FortiSandbox PaaS 5.0 versions 5.0.4 through 5.0.5 need the same 5.0.6 upgrade path.

Product / Deployment VariantAffected VersionsRecommended RemediationSeverity & Classification
FortiSandbox (On-Premises)5.0.0 through 5.0.5
4.4.0 through 4.4.8
Upgrade to version 5.0.6 or above
Upgrade to version 4.4.9 or above
High (CVSS 8.9) / CWE-284 Improper Access Control
FortiSandbox Cloud5.0.4 through 5.0.5Upgrade to version 5.0.6 or aboveHigh (CVSS 8.9) / Unauthenticated info disclosure
FortiSandbox PaaS5.0.4 through 5.0.5Upgrade to version 5.0.6 or aboveHigh (CVSS 8.9) / Web UI authentication bypass
Unaffected ReleasesFortiSandbox 5.2, Cloud 4.4, PaaS 5.2No action requiredNot vulnerable to CVE-2026-26084

Attackers who gain visibility into sandbox configurations, sample metadata, or internal logs can use that intelligence to evade detection or identify other soft spots in an organization’s infrastructure.

This disclosure also fits a broader pattern seen across Fortinet’s product line over the past several months, where multiple FortiSandbox and related appliances have faced scrutiny for authorization weaknesses in their web-based management consoles.

Organizations running any vulnerable version of FortiSandbox, FortiSandbox Cloud, or FortiSandbox PaaS should move to the corresponding fixed release without delay.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.



Source link