ZDI-26-645: Fortinet FortiSandbox write_remote_backup_to_crontab cronValue Command Injection Remote Code Execution Vulnerability
ZDI publishes ZDI-26-645 for CVE-2026-84387, an authenticated command injection RCE in Fortinet FortiSandbox via crontab backup, rated CVSS 7.2.
Zero Day Initiative published advisory ZDI-26-645 describing a command injection flaw in Fortinet FortiSandbox's write_remote_backup_to_crontab function. Remote authenticated attackers can execute arbitrary code through the cronValue parameter. ZDI rated the issue CVSS 7.2 and assigned CVE-2026-84387.
- Command injection via cronValue in the crontab backup function
- Authentication is required to exploit the flaw
- CVSS 7.2; tracked as CVE-2026-84387
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-84387 | High-Privilege Command Injection in Fortinet FortiSandbox CVE-2026-84387 is a command injection flaw (CWE-77) in Fortinet FortiSandbox in which special elements used in a command are not properly neutralized, allowing an attacker to inject and execute unauthorized commands or code on the appliance. The CVSS vector indicates the flaw is reachable over the network (AV:N) but requires the attacker to already hold high-privilege credentials (PR:H), such as an administrative account, with no user interaction required; the exact entry point in the product interface is not detailed in the available data. Successful exploitation carries high impact across confidentiality, integrity, and availability, effectively giving the attacker arbitrary command execution on a security appliance that handles untrusted analyzed files. All FortiSandbox deployments running versions 4.4.0 through 4.4.9, 5.0.0 through 5.0.6, or 5.2.0 are affected. No public proof-of-concept is known, the flaw is not on the CISA KEV list, and EPSS estimates only about a 0.9% probability of exploitation in the next 30 days, so no active exploitation is currently known. Do: Check Fortinet's PSIRT advisory (CVE-2026-84387) for the fixed release and upgrade all FortiSandbox units off the affected versions (4.4.0-4.4.9, 5.0.0-5.0.6, and 5.2.0). Until patched, restrict high-privilege administrative access to the FortiSandbox management interface to trusted networks or VPN, since exploitation requires administrative credentials, and audit privileged accounts for unusual activity. Monitor appliance logs for unexpected commands, processes, or configuration changes. | 7.2 | <1% |
| moderate~1,000-10,000 deployed appliances (best estimate; only a subset are internet-exposed) |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fortinet FortiSandbox. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-84387.
This source does not provide full text. Read it at zerodayinitiative.com.