ZeroHour

Search: “paas”

288 stories

FortiSandbox Vulnerability Allows Attackers to Access Sensitive Information via Crafted HTTP Requests

Fortinet disclosed CVE-2026-26084 (CVSS 8.9), an unauthenticated information-disclosure flaw in the FortiSandbox web UI, urging upgrades.

Fortinet patched CVE-2026-26084, a CWE-284 improper access control flaw in the shared web UI of FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS that lets unauthenticated attackers read sensitive data via crafted HTTP requests. Affected releases include FortiSandbox 5.0.0-5.0.5 and 4.4.0-4.4.8, Cloud 5.0.4-5.0.5, and PaaS 5.0.4-5.0.5; fixes arrive in 5.0.6+ and 4.4.9+, while FortiSandbox 5.2 and Cloud 4.4 are unaffected. The issue was found internally by Fortinet's Product Security team, and the company reports no evidence of exploitation in the wild. Disclosure carries only confidentiality impact, but exposed sandbox configurations and logs could aid follow-on attacks.

Fortinet FortiSandbox Vulnerability Allows Unauthenticated Attackers to Access Sensitive Information

Fortinet fixed CVE-2026-26084, an unauthenticated access-control flaw in FortiSandbox GUI rated 8.9 CVSS, with no known exploitation yet.

Fortinet disclosed CVE-2026-26084 (advisory FG-IR-26-166), a CWE-284 improper access control flaw in the GUI of FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS, rated 8.9 CVSS v3.1. An unauthenticated remote attacker can send specially crafted HTTP requests to control NAT rules and expose sensitive information. Affected versions include FortiSandbox 4.4.0-4.4.8 and 5.0.0-5.0.5 (plus Cloud/PaaS 5.0.4-5.0.5), fixed in 4.4.9 and 5.0.6. Fortinet researcher Adham El Karn found the flaw internally and the September 8 advisory reports no known exploitation.

GBHackers · 7d agoVulnerabilityCVE-2026-26084

Unauthenticated Control of NAT Rules Leading to Exposure of Sensitive Information

Fortinet fixed an improper access control flaw (CVSS 8.9) in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS letting unauthenticated attackers access sensitive information.

Fortinet advisory FG-IR-26-166 discloses an improper access control vulnerability (CWE-284) in the FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS web UI, rated CVSSv3 8.9. The advisory title indicates unauthenticated control of NAT rules leading to exposure of sensitive information. An unauthenticated attacker can access sensitive data via crafted HTTP requests. The advisory was revised on 2026-09-08.

Fortinet PSIRT · 8d agoAdvisory