ZeroHour

CVE-2026-84387

moderate

High-Privilege Command Injection in Fortinet FortiSandbox

CVSS 3.1
7.2 high
EPSS
<1%p57
Published
()
Modified
AI analysis

CVE-2026-84387 is a command injection flaw (CWE-77) in Fortinet FortiSandbox in which special elements used in a command are not properly neutralized, allowing an attacker to inject and execute unauthorized commands or code on the appliance. The CVSS vector indicates the flaw is reachable over the network (AV:N) but requires the attacker to already hold high-privilege credentials (PR:H), such as an administrative account, with no user interaction required; the exact entry point in the product interface is not detailed in the available data. Successful exploitation carries high impact across confidentiality, integrity, and availability, effectively giving the attacker arbitrary command execution on a security appliance that handles untrusted analyzed files. All FortiSandbox deployments running versions 4.4.0 through 4.4.9, 5.0.0 through 5.0.6, or 5.2.0 are affected. No public proof-of-concept is known, the flaw is not on the CISA KEV list, and EPSS estimates only about a 0.9% probability of exploitation in the next 30 days, so no active exploitation is currently known.

What to do: Check Fortinet's PSIRT advisory (CVE-2026-84387) for the fixed release and upgrade all FortiSandbox units off the affected versions (4.4.0-4.4.9, 5.0.0-5.0.6, and 5.2.0). Until patched, restrict high-privilege administrative access to the FortiSandbox management interface to trusted networks or VPN, since exploitation requires administrative credentials, and audit privileged accounts for unusual activity. Monitor appliance logs for unexpected commands, processes, or configuration changes.

Affected
Fortinet FortiSandbox5.2.0
Fortinet FortiSandbox5.0.0 through 5.0.6
Fortinet FortiSandbox4.4.0 through 4.4.9
Estimated exposure
moderate~1,000-10,000 deployed appliances (best estimate; only a subset are internet-exposed) — FortiSandbox is a specialized enterprise malware-analysis appliance typically deployed alongside FortiGate/FortiMail rather than mass-market software, and public internet scans show exposed units numbering only in the low thousands, so…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A improper neutralization of special elements used in a command ('command injection') vulnerability in Fortinet FortiSandbox 5.2.0, FortiSandbox 5.0.0 through 5.0.6, FortiSandbox 4.4.0 through 4.4.9 may allow attacker to execute unauthorized code or commands via

Weakness
CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

ZDI-26-645: Fortinet FortiSandbox write_remote_backup_to_crontab cronValue Command Injection Remote Code Execution Vulnerability

ZDI publishes ZDI-26-645 for CVE-2026-84387, an authenticated command injection RCE in Fortinet FortiSandbox via crontab backup, rated CVSS 7.2.

Zero Day Initiative published advisory ZDI-26-645 describing a command injection flaw in Fortinet FortiSandbox's write_remote_backup_to_crontab function. Remote authenticated attackers can execute arbitrary code through the cronValue parameter. ZDI rated the issue CVSS 7.2 and assigned CVE-2026-84387.