Fortinet FortiSandbox CVE-2026-26084 (CVSS 8.9): Unauthenticated Info-Exposure Flaw Patched; Canadian Cyber Centre Urges Broad Fortinet Updates
Fortinet fixed CVE-2026-26084, an unauthenticated improper access control flaw (CVSS 8.9) in the FortiSandbox GUI that lets attackers control NAT rules and expose sensitive data; Canada's Cyber Centre then relayed the advisories (AV26-898) urging patching…
Fortinet's September 8 advisory FG-IR-26-166 discloses CVE-2026-26084, a CWE-284 improper access control vulnerability in the GUI of FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS, rated 8.9 on CVSS v3.1. An unauthenticated remote attacker can send specially crafted HTTP requests to control NAT rules and expose sensitive information. Affected versions are FortiSandbox 4.4.0-4.4.8 and 5.0.0-5.0.5, plus FortiSandbox Cloud and PaaS 5.0.4-5.0.5; fixes are available in 4.4.9 and 5.0.6, and the 5.2 line is unaffected. The flaw was found internally by Fortinet researcher Adham El Karn, and no known exploitation or public PoC has been reported. On September 9, the Canadian Centre for Cyber Security published advisory AV26-898 relaying Fortinet PSIRT advisories covering FortiOS 7.6.1-7.6.6, FortiProxy 7.6.2-7.6.6, FortiPAM Chrome extensions 7.4/8.0, FortiSandbox 4.4 and 5.0, FortiSandbox Cloud/PaaS 5.0.4-5.0.5, and FortiMonitorOnSight 7.2, urging administrators to review the linked advisories and apply updates. The Canadian bulletin itself lists no individual CVE identifiers or exploitation details.
- CVE-2026-26084, Fortinet advisory FG-IR-26-166, disclosed September 8, 2026.
- CWE-284 improper access control in the FortiSandbox GUI; rated CVSS 8.9 (v3.1).
- An unauthenticated remote attacker can send specially crafted HTTP requests to control NAT rules and expose sensitive information.
- Affected versions: FortiSandbox 4.4.0-4.4.8 and 5.0.0-5.0.5; FortiSandbox Cloud and PaaS 5.0.4-5.0.5.
- Fixed in FortiSandbox 4.4.9 and 5.0.6; the 5.2 line is unaffected.
- Found internally by Fortinet researcher Adham El Karn; no known exploitation or public PoC reported.
- Canadian Centre for Cyber Security advisory AV26-898 (September 9) relays Fortinet PSIRT advisories spanning FortiOS 7.6.1-7.6.6, FortiProxy 7.6.2-7.6.6, FortiPAM Chrome extensions 7.4/8.0, FortiSandbox 4.4/5.0, FortiSandbox Cloud/PaaS…
- Defensive guidance: restrict FortiSandbox GUI access to management networks and review logs for anomalous requests.
Coverage timelineoldest first · each row is one article
- · 6d agoFortinet FortiSandbox Vulnerability Allows Unauthenticated Attackers to Access Sensitive Information
GBHackers· 58
Fortinet fixed CVE-2026-26084, an unauthenticated access-control flaw in FortiSandbox GUI rated 8.9 CVSS, with no known exploitation yet.
- · 6d agoFortinet security advisory (AV26-898)
Canadian Centre for Cyber Security· 26
Canadian Cyber Centre advisory AV26-898 flags Fortinet vulnerabilities across FortiOS, FortiProxy, FortiPAM, FortiSandbox and FortiMonitorOnSight, urging administrators to apply updates
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-26084 | Improper Access Control in Fortinet FortiSandbox Exposes Sensitive Data CVE-2026-26084 is an improper access control flaw (CWE-284) in the web interface of Fortinet's FortiSandbox threat-analysis product line, affecting on-premises 4.4.x and 5.0.x releases as well as the FortiSandbox Cloud and PaaS offerings. An unauthenticated attacker can trigger it remotely by sending crafted HTTP requests to the affected FortiSandbox web service, bypassing access controls without needing credentials or user interaction. A successful attacker gains access to sensitive information handled by the appliance; Fortinet's critical 9.9 CVSS score also reflects a scope change with a high availability-impact component, so defenders should treat the practical impact as potentially broader than simple information disclosure. Any organization running affected versions of FortiSandbox, FortiSandbox Cloud, or FortiSandbox PaaS is in scope, though the product's enterprise appliance/cloud deployment model means the affected population is far smaller than endpoint or firewall software. There is no evidence of exploitation so far: the flaw is not in CISA KEV, has no known public proof-of-concept, and EPSS assigns roughly a 0.2% probability of exploitation within 30 days. Do: Upgrade all FortiSandbox deployments to a fixed release outside the affected ranges — later than 5.0.5 on the 5.0 branch, later than 4.4.8 on the 4.4 branch, and later than 5.0.5 for Cloud and PaaS — following Fortinet's PSIRT advisory. Until patched, restrict HTTP/HTTPS management access to the appliance to trusted management networks or VPN, since the flaw is reachable without authentication. Monitor Fortinet's advisory and the CISA KEV catalog for updates, given the critical severity score. | 9.9 | <1% |
| moderatelikely on the order of several thousand to ~10,000 deployed FortiSandbox appliances/instances worldwide, with only a smaller subset exposing the vulnerable web… |