Unauthenticated Control of NAT Rules Leading to Exposure of Sensitive Information
Fortinet fixed an improper access control flaw (CVSS 8.9) in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS letting unauthenticated attackers access sensitive information.
Fortinet advisory FG-IR-26-166 discloses an improper access control vulnerability (CWE-284) in the FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS web UI, rated CVSSv3 8.9. The advisory title indicates unauthenticated control of NAT rules leading to exposure of sensitive information. An unauthenticated attacker can access sensitive data via crafted HTTP requests. The advisory was revised on 2026-09-08.
- CVSSv3 8.9 improper access control (CWE-284) in web UI
- Unauthenticated attacker can access sensitive information
- Affects FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS
- Advisory title cites unauthenticated NAT rule control
CVSSv3 Score: 8.9 An improper access control vulnerability [CWE-284] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to access sensitive information via crafted HTTP requests. Revised on 2026-09-08 00:00:00
This source does not provide full text. Read it at fortiguard.fortinet.com.