AI analysis
CVE-2026-84387 is a command injection flaw (CWE-77) in Fortinet FortiSandbox in which special elements used in a command are not properly neutralized, allowing an attacker to inject and execute unauthorized commands or code on the appliance. The CVSS vector indicates the flaw is reachable over the network (AV:N) but requires the attacker to already hold high-privilege credentials (PR:H), such as an administrative account, with no user interaction required; the exact entry point in the product interface is not detailed in the available data. Successful exploitation carries high impact across confidentiality, integrity, and availability, effectively giving the attacker arbitrary command execution on a security appliance that handles untrusted analyzed files. All FortiSandbox deployments running versions 4.4.0 through 4.4.9, 5.0.0 through 5.0.6, or 5.2.0 are affected. No public proof-of-concept is known, the flaw is not on the CISA KEV list, and EPSS estimates only about a 0.9% probability of exploitation in the next 30 days, so no active exploitation is currently known.
What to do: Check Fortinet's PSIRT advisory (CVE-2026-84387) for the fixed release and upgrade all FortiSandbox units off the affected versions (4.4.0-4.4.9, 5.0.0-5.0.6, and 5.2.0). Until patched, restrict high-privilege administrative access to the FortiSandbox management interface to trusted networks or VPN, since exploitation requires administrative credentials, and audit privileged accounts for unusual activity. Monitor appliance logs for unexpected commands, processes, or configuration changes.
Affected
| Fortinet FortiSandbox | 5.2.0 |
| Fortinet FortiSandbox | 5.0.0 through 5.0.6 |
| Fortinet FortiSandbox | 4.4.0 through 4.4.9 |
Estimated exposure
moderate~1,000-10,000 deployed appliances (best estimate; only a subset are internet-exposed) — FortiSandbox is a specialized enterprise malware-analysis appliance typically deployed alongside FortiGate/FortiMail rather than mass-market software, and public internet scans show exposed units numbering only in the low thousands, so…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A improper neutralization of special elements used in a command ('command injection') vulnerability in Fortinet FortiSandbox 5.2.0, FortiSandbox 5.0.0 through 5.0.6, FortiSandbox 4.4.0 through 4.4.9 may allow attacker to execute unauthorized code or commands via