ZeroHour

CVE-2026-39813

large

Path Traversal Privilege Escalation in Fortinet FortiSandbox 4.4/5.0

CVSS 3.1
9.8 critical
EPSS
23%p98
Published
()
Modified
AI analysis

CVE-2026-39813 is a path traversal ('../filedir') vulnerability in Fortinet FortiSandbox that can be triggered with specially crafted HTTP requests. The CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates the flaw is reachable over the network, with no authentication or user interaction required. A successful attacker gains escalation of privilege on the FortiSandbox appliance, and the 9.8 (critical) score reflects potential for high confidentiality, integrity, and availability impact. All FortiSandbox deployments running 4.4.0 through 4.4.8 or 5.0.0 through 5.0.5 are affected. The flaw is not yet in CISA's KEV catalog and has no known public PoC, but news reports indicate attackers are actively exploiting a set of three critical FortiSandbox bugs Fortinet disclosed in April, which likely includes this vulnerability; its EPSS score of 23.4% (98th percentile) supports elevated near-term exploitation risk.

What to do: Upgrade FortiSandbox to a fixed release beyond the affected ranges — later than 5.0.5 for the 5.0 branch and later than 4.4.8 for the 4.4 branch — as specified in the Fortinet PSIRT advisory, and apply fixes for the other reported FortiSandbox bugs at the same time. Until patching is complete, restrict access to the FortiSandbox HTTP management interface so it is not reachable from untrusted networks or the internet. Monitor the appliance for signs of exploitation and check Fortinet's advisory for updated indicators and fixed builds.

Affected
Fortinet FortiSandbox5.0.0 through 5.0.5
Fortinet FortiSandbox4.4.0 through 4.4.8
Estimated exposure
largelikely tens of thousands of FortiSandbox appliance/VM deployments worldwide, with only a subset of management interfaces exposed to the internet — FortiSandbox is a widely deployed companion appliance/VM attached to enterprise FortiGate estates, giving it an installed base plausibly in the tens of thousands, though far smaller than FortiGate's and with most management HTTP interfaces…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially crafted HTTP requests.

Vendors
fortinet
Products
fortisandbox
Weakness
CWE-24
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news