ZeroHour
Security Affairspublished ()ingested @securityaffairs

Critical fortinet vulnerabilities fixed in FortiSandbox and FortiAuthenticator

criticalVulnerability exploited in the wildimportance 60CVE-2026-44277CVE-2026-26083

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-26083
A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 through 5.0.5, Fo

A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 through 5.0.5, FortiSandbox PaaS 23.4 all versions, FortiSandbox PaaS 23.3 all versions, FortiSandbox PaaS 23.1 all versions, FortiSandbox PaaS 22.2 all versions, FortiSandbox PaaS 22.1 all versions, FortiSandbox PaaS 21.4 all versions, FortiSandbox PaaS 21.3 all versions, FortiSandbox PaaS 5.0.0 through 5.0.1, FortiSandbox PaaS 4.4.5 through 4.4.8 may allow an unauthenticated attacker to execute unauthorized code or commands via HTTP requests.

NVD description · AI analysis pending
9.8<1%
  • fortinet fortisandbox
  • fortinet fortisandbox cloud
  • fortinet fortisandbox paas
CVE-2026-44277
A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticat

A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attacker to execute unauthorized code or commands via crafted requests.

NVD description · AI analysis pending
9.8<1%
  • fortinet fortiauthenticator
Full article245 words · extracted from securityaffairs.com · click to collapse

Fortinet patched critical flaws in FortiSandbox and FortiAuthenticator that could let attackers remotely execute code on unpatched systems.

Fortinet addressed two critical vulnerabilities affecting FortiSandbox and FortiAuthenticator. The flaws could allow attackers to execute arbitrary commands or code on unpatched systems.

The first vulnerability, tracked as CVE-2026-44277, is an improper access control issue in FortiAuthenticator.

“An Improper Access Control vulnerability [CWE-284] in FortiAuthenticator may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.” reads the advisory.

Below are the impacted versions:

VersionAffectedSolution
FortiAuthenticator 8.08.0.2Upgrade to 8.0.3 or above
FortiAuthenticator 8.08.0.0Upgrade to 8.0.3 or above
FortiAuthenticator 6.66.6.0 through 6.6.8Upgrade to 6.6.9 or above
FortiAuthenticator 6.56.5.0 through 6.5.6Upgrade to 6.5.7 or above

The vulnerability doesn’t affect FortiAuthenticator Cloud.

Fortinet experts discovered the flaw as part of an internal audit.

The second flaw addressed by the cybersecurity vendor is a missing authorization issue, tracked as CVE-2026-26083, in FortiSandbox. An attacker can trigger the flaw to achieve remote code execution on vulnerable systems.

“A missing authorization vulnerability [CWE-862] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to execute unauthorized code or commands via HTTP requests.” reads the advisory.

Neither flaw has been exploited in in-the-wild attacks.

Adham El Karn from the Fortinet Product Security team discovered and reported the issue internally.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, FortiAuthenticator)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/192047/security/critical-fortinet-vulnerabilities-fixed-in-fortisandbox-and-fortiauthenticator.html