ZeroHour
GBHackerspublished ()ingested Divya

Fortinet FortiSandbox Vulnerability Allows Unauthenticated Attackers to Access Sensitive Information

AI summary · glm-5.3-flash

Fortinet fixed CVE-2026-26084, an unauthenticated access-control flaw in FortiSandbox GUI rated 8.9 CVSS, with no known exploitation yet.

Fortinet disclosed CVE-2026-26084 (advisory FG-IR-26-166), a CWE-284 improper access control flaw in the GUI of FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS, rated 8.9 CVSS v3.1. An unauthenticated remote attacker can send specially crafted HTTP requests to control NAT rules and expose sensitive information. Affected versions include FortiSandbox 4.4.0-4.4.8 and 5.0.0-5.0.5 (plus Cloud/PaaS 5.0.4-5.0.5), fixed in 4.4.9 and 5.0.6. Fortinet researcher Adham El Karn found the flaw internally and the September 8 advisory reports no known exploitation.

  • Unauthenticated HTTP requests to the GUI can expose sensitive data via NAT rule control.
  • Fixed versions are 4.4.9+ and 5.0.6+; 5.2 lines are unaffected.
  • Fortinet assigned CVSS 8.9; no public PoC or exploitation reported.
  • Defenders should restrict GUI access to management networks and review logs for anomalous requests.
VendorsFortinet
ProductsFortiSandbox
OrganizationsFortinet PSIRT

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-26084
Improper Access Control in Fortinet FortiSandbox Exposes Sensitive Data

CVE-2026-26084 is an improper access control flaw (CWE-284) in the web interface of Fortinet's FortiSandbox threat-analysis product line, affecting on-premises 4.4.x and 5.0.x releases as well as the FortiSandbox Cloud and PaaS offerings. An unauthenticated attacker can trigger it remotely by sending crafted HTTP requests to the affected FortiSandbox web service, bypassing access controls without needing credentials or user interaction. A successful attacker gains access to sensitive information handled by the appliance; Fortinet's critical 9.9 CVSS score also reflects a scope change with a high availability-impact component, so defenders should treat the practical impact as potentially broader than simple information disclosure. Any organization running affected versions of FortiSandbox, FortiSandbox Cloud, or FortiSandbox PaaS is in scope, though the product's enterprise appliance/cloud deployment model means the affected population is far smaller than endpoint or firewall software. There is no evidence of exploitation so far: the flaw is not in CISA KEV, has no known public proof-of-concept, and EPSS assigns roughly a 0.2% probability of exploitation within 30 days.

Do: Upgrade all FortiSandbox deployments to a fixed release outside the affected ranges — later than 5.0.5 on the 5.0 branch, later than 4.4.8 on the 4.4 branch, and later than 5.0.5 for Cloud and PaaS — following Fortinet's PSIRT advisory. Until patched, restrict HTTP/HTTPS management access to the appliance to trusted management networks or VPN, since the flaw is reachable without authentication. Monitor Fortinet's advisory and the CISA KEV catalog for updates, given the critical severity score.

9.9<1%
  • Fortinet FortiSandbox 5.0.0 through 5.0.5
  • Fortinet FortiSandbox 4.4.0 through 4.4.8
  • Fortinet FortiSandbox Cloud 5.0.4 through 5.0.5
  • +1 more
moderatelikely on the order of several thousand to ~10,000 deployed FortiSandbox appliances/instances worldwide, with only a smaller subset exposing the vulnerable web…
Full article555 words · extracted from gbhackers.com · click to collapse

Fortinet has disclosed a critical vulnerability involving improper access control in the FortiSandbox web interfaces. This issue could allow an unauthenticated remote attacker to access sensitive information by sending specially crafted HTTP requests.

The vulnerability is tracked as CVE-2026-26084 and documented in advisory FG-IR-26-166. It affects the graphical user interface (GUI) component of FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS.

Fortinet has assigned a CVSS v3.1 score of 8.9 to this vulnerability, indicating high severity due to factors such as network reachability, low attack complexity, the absence of required privileges or user interaction, and potential impacts on confidentiality, integrity, and availability.

Fortinet FortiSandbox Vulnerability

The issue is classified under CWE-284, which pertains to Improper Access Control. Fortinet describes the vulnerability as “unauthenticated control of NAT rules leading to the exposure of sensitive information.”

In practical terms, this means that vulnerable devices may fail to correctly enforce authorization checks for a web interface function related to Network Address Translation (NAT) rules.

A remote attacker who can access the management interface could submit specially formatted HTTP requests without prior authentication. Fortinet’s advisory does not specify the exact request format, the records exposed, or provide a proof of concept, so defenders should not assume only low-value configuration data is at risk.

The vulnerable versions include FortiSandbox 5.0.0 to 5.0.5 and FortiSandbox 4.4.0 to 4.4.8. Additionally, FortiSandbox Cloud versions 5.0.4 to 5.0.5 and FortiSandbox PaaS versions 5.0.4 to 5.0.5 are also affected.

Organizations using the impacted 5.0 product line should upgrade to version 5.0.6 or later, while those on the 4.4 branch must move to version 4.4.9 or later. Fortinet notes that FortiSandbox 5.2, FortiSandbox Cloud 4.4, and FortiSandbox PaaS 5.2 are not affected by this vulnerability.

Because exploitation does not require credentials, exposure of the administrative GUI significantly increases risk. Security teams should promptly identify FortiSandbox instances, including hosted Cloud and PaaS deployments, confirm their running versions, and prioritize remediation for interfaces accessible from the internet or less-trusted network segments.

Until patching is complete, administrators should restrict GUI access to dedicated management networks, enforce allowlisting through firewalls or VPN gateways, and review reverse-proxy and NAT configurations that might unintentionally expose the service.

Teams should also analyze web-server, application, and perimeter logs for any unusual requests targeting FortiSandbox management paths, particularly those from unfamiliar sources, repeated malformed HTTP parameters, and unexpected changes to NAT configurations.

Any suspected compromise should trigger a review of appliance settings, privileged accounts, connected network paths, and potentially exposed information. Fortinet reports that Adham El Karn of its Product Security team discovered the vulnerability internally, and there have been no known exploitations as of the advisory’s publication on September 8.

Fortinet’s Product Security Incident Response Team (PSIRT) manages the reporting and resolution of vulnerabilities. Organizations should retain relevant logs before performing upgrades, document exposed management endpoints, and ensure that compensating controls do not interfere with sandbox submissions, analyses, or operations during remediation.

The lack of public exploitation should not delay remediation efforts, as pre-authentication flaws in security management interfaces may become attractive targets once technical details are disclosed.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/fortinet-fortisandbox-vulnerability-3/