FortiSandbox Vulnerability Allows Attackers to Access Sensitive Information via Crafted HTTP Requests
Fortinet disclosed CVE-2026-26084 (CVSS 8.9), an unauthenticated information-disclosure flaw in the FortiSandbox web UI, urging upgrades.
Fortinet patched CVE-2026-26084, a CWE-284 improper access control flaw in the shared web UI of FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS that lets unauthenticated attackers read sensitive data via crafted HTTP requests. Affected releases include FortiSandbox 5.0.0-5.0.5 and 4.4.0-4.4.8, Cloud 5.0.4-5.0.5, and PaaS 5.0.4-5.0.5; fixes arrive in 5.0.6+ and 4.4.9+, while FortiSandbox 5.2 and Cloud 4.4 are unaffected. The issue was found internally by Fortinet's Product Security team, and the company reports no evidence of exploitation in the wild. Disclosure carries only confidentiality impact, but exposed sandbox configurations and logs could aid follow-on attacks.
- CVE-2026-26084 rated CVSS 8.9, unauthenticated info disclosure via crafted HTTP requests
- Impacts FortiSandbox on-premises, Cloud, and PaaS web UI components
- Fix in 5.0.6+ or 4.4.9+; 5.2 and Cloud 4.4 unaffected
- No user interaction or privileges needed; no code execution
- Fortinet says no evidence of in-the-wild exploitation
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-26084 | Improper Access Control in Fortinet FortiSandbox Exposes Sensitive Data CVE-2026-26084 is an improper access control flaw (CWE-284) in the web interface of Fortinet's FortiSandbox threat-analysis product line, affecting on-premises 4.4.x and 5.0.x releases as well as the FortiSandbox Cloud and PaaS offerings. An unauthenticated attacker can trigger it remotely by sending crafted HTTP requests to the affected FortiSandbox web service, bypassing access controls without needing credentials or user interaction. A successful attacker gains access to sensitive information handled by the appliance; Fortinet's critical 9.9 CVSS score also reflects a scope change with a high availability-impact component, so defenders should treat the practical impact as potentially broader than simple information disclosure. Any organization running affected versions of FortiSandbox, FortiSandbox Cloud, or FortiSandbox PaaS is in scope, though the product's enterprise appliance/cloud deployment model means the affected population is far smaller than endpoint or firewall software. There is no evidence of exploitation so far: the flaw is not in CISA KEV, has no known public proof-of-concept, and EPSS assigns roughly a 0.2% probability of exploitation within 30 days. Do: Upgrade all FortiSandbox deployments to a fixed release outside the affected ranges — later than 5.0.5 on the 5.0 branch, later than 4.4.8 on the 4.4 branch, and later than 5.0.5 for Cloud and PaaS — following Fortinet's PSIRT advisory. Until patched, restrict HTTP/HTTPS management access to the appliance to trusted management networks or VPN, since the flaw is reachable without authentication. Monitor Fortinet's advisory and the CISA KEV catalog for updates, given the critical severity score. | 9.9 | <1% |
| moderatelikely on the order of several thousand to ~10,000 deployed FortiSandbox appliances/instances worldwide, with only a smaller subset exposing the vulnerable web… |
Full article682 words · extracted from cybersecuritynews.com · click to collapse
Fortinet has disclosed a new high-severity vulnerability affecting its FortiSandbox platform, warning that unauthenticated attackers could exploit weaknesses in the product’s web interface to siphon off sensitive information without ever needing valid credentials.
The flaw, tracked as CVE-2026-26084, stems from improper access control in the graphical user interface component that FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS all share, and it has been assigned a CVSS v3.1 score of 8.9, placing it firmly in the high-severity category.
FortiSandbox is widely deployed across enterprise and government networks as an advanced threat detection appliance, using sandboxing techniques to analyze suspicious files and network traffic for zero-day malware and other advanced threats.
FortiSandbox Vulnerability Exposes Sensitive Information
According to Fortinet’s advisory, the vulnerability is classified under CWE-284, Improper Access Control. In practical terms, this means the WEB UI fails to properly verify whether a request originates from an authorized session before returning sensitive data.
An attacker who understands the structure of the application’s internal API endpoints can craft specially formed HTTP requests and send them directly to the FortiSandbox web interface, bypassing the authentication checks that would normally gate access to that information.
The advisory notes that exploitation requires no user interaction and no prior privileges, which is reflected in the CVSS vector’s designation of the attack as unauthenticated.
While the vulnerability does not grant an attacker the ability to modify data or execute code, the confidentiality impact is still significant enough to warrant urgent patching, since exposed information from a security appliance like FortiSandbox could include configuration details, logs, or other operational data that attackers could use to plan follow-on intrusions.
Fortinet credits Adham El Karn of its own Product Security team with discovering and reporting the issue internally, rather than through an external researcher or bug bounty submission.
The company has stated there is no evidence that the vulnerability has been exploited in the wild, and it carries an “Internal” discovery tag along with a “No” rating for known exploitation as of the publication date.
FortiSandbox 5.2 is not affected, giving administrators on the latest version extra time to manage it. However, FortiSandbox 5.0 versions from 5.0.0 through 5.0.5 are vulnerable, and Fortinet recommends upgrading to 5.0.6 or later to close the gap. Similarly, FortiSandbox 4.4 versions between 4.4.0 and 4.4.8 are exposed, with 4.4.9 or above serving as the fixed release.
The cloud and platform-as-a-service variants show a mixed picture. FortiSandbox Cloud 5.0 is affected in the 5.0.4 through 5.0.5 range, again requiring an upgrade to 5.0.6 or above, while FortiSandbox Cloud 4.4 escapes the issue entirely.
On the PaaS side, FortiSandbox PaaS 5.2 is unaffected, but FortiSandbox PaaS 5.0 versions 5.0.4 through 5.0.5 need the same 5.0.6 upgrade path.
| Product / Deployment Variant | Affected Versions | Recommended Remediation | Severity & Classification |
| FortiSandbox (On-Premises) | 5.0.0 through 5.0.5 4.4.0 through 4.4.8 | Upgrade to version 5.0.6 or above Upgrade to version 4.4.9 or above | High (CVSS 8.9) / CWE-284 Improper Access Control |
| FortiSandbox Cloud | 5.0.4 through 5.0.5 | Upgrade to version 5.0.6 or above | High (CVSS 8.9) / Unauthenticated info disclosure |
| FortiSandbox PaaS | 5.0.4 through 5.0.5 | Upgrade to version 5.0.6 or above | High (CVSS 8.9) / Web UI authentication bypass |
| Unaffected Releases | FortiSandbox 5.2, Cloud 4.4, PaaS 5.2 | No action required | Not vulnerable to CVE-2026-26084 |
Attackers who gain visibility into sandbox configurations, sample metadata, or internal logs can use that intelligence to evade detection or identify other soft spots in an organization’s infrastructure.
This disclosure also fits a broader pattern seen across Fortinet’s product line over the past several months, where multiple FortiSandbox and related appliances have faced scrutiny for authorization weaknesses in their web-based management consoles.
Organizations running any vulnerable version of FortiSandbox, FortiSandbox Cloud, or FortiSandbox PaaS should move to the corresponding fixed release without delay.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/fortisandbox-vulnerability-access-sensitive-data/