ZeroHour
Story · 1 source · 1 articlefirst updated ()

Fortinet Patches FortiSandbox Flaw CVE-2026-26084 Letting Unauthenticated Attackers Expose Sensitive Data via Crafted HTTP Requests

What's new: GBHackers' report adds details absent from the initial Cyber Security News writeup: the advisory ID FG-IR-26-166, the September 8, 2026 advisory publication date, the CVSS v3.1 designation, the researcher credit (Adham El Karn), and the specific mechanism that crafted HTTP requests can control NAT rules. All other technical details—CVE ID, CVSS 8.9 score, CWE-284 classification, affected and…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Fortinet disclosed and fixed CVE-2026-26084 (advisory FG-IR-26-166, CVSS 8.9 v3.1), an unauthenticated CWE-284 improper access control flaw in the shared web UI of FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS; crafted HTTP requests can control NAT…

Fortinet disclosed CVE-2026-26084 in advisory FG-IR-26-166, published September 8, 2026: a CWE-284 improper access control flaw in the shared web UI/GUI of FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS, rated CVSS 8.9 (v3.1). An unauthenticated remote attacker can send specially crafted HTTP requests to the GUI to expose sensitive information; GBHackers specifies that these requests can control NAT rules, while Cyber Security News characterizes the flaw generally as reading sensitive data via crafted HTTP requests. Impact is confidentiality-only, with no user interaction, no privileges required, and no code execution. Affected versions are FortiSandbox 4.4.0-4.4.8 and 5.0.0-5.0.5, plus FortiSandbox Cloud 5.0.4-5.0.5 and FortiSandbox PaaS 5.0.4-5.0.5. Fixes ship in FortiSandbox 4.4.9 and 5.0.6 or later; FortiSandbox 5.2 and FortiSandbox Cloud 4.4 are unaffected. The flaw was found internally by Fortinet's Product Security team, with GBHackers identifying the researcher as Adham El Karn. At disclosure, Fortinet reported no evidence of in-the-wild exploitation and no public PoC is known. Defenders are advised to restrict GUI access to management networks and review logs for anomalous requests; exposed sandbox configurations and logs could aid follow-on attacks. The two reports do not conflict on the technical details of CVE-2026-26084.

  • CVE-2026-26084, tracked in Fortinet advisory FG-IR-26-166 published September 8, 2026, is rated CVSS 8.9 (v3.1).
  • The flaw is CWE-284 improper access control in the shared web UI/GUI of FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS.
  • An unauthenticated remote attacker can send specially crafted HTTP requests to expose sensitive information; per GBHackers, the requests can also control NAT rules.
  • Impact is confidentiality-only: no user interaction or privileges required, and no code execution.
  • Affected versions: FortiSandbox 4.4.0-4.4.8 and 5.0.0-5.0.5; FortiSandbox Cloud 5.0.4-5.0.5; FortiSandbox PaaS 5.0.4-5.0.5.
  • Fixed in FortiSandbox 4.4.9+ and 5.0.6+; FortiSandbox 5.2 and FortiSandbox Cloud 4.4 are unaffected.
  • The flaw was found internally by Fortinet's Product Security team; GBHackers names the researcher as Adham El Karn.
  • Fortinet reports no evidence of in-the-wild exploitation and no public PoC is known.
VendorsFortinet
ProductsFortiSandbox
OrganizationsFortinet PSIRT

Coverage timeline

  1. · 7d ago
    Cyber Security News· 48
    FortiSandbox Vulnerability Allows Attackers to Access Sensitive Information via Crafted HTTP Requests

    Fortinet disclosed CVE-2026-26084 (CVSS 8.9), an unauthenticated information-disclosure flaw in the FortiSandbox web UI, urging upgrades.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-26084
Improper Access Control in Fortinet FortiSandbox Exposes Sensitive Data

CVE-2026-26084 is an improper access control flaw (CWE-284) in the web interface of Fortinet's FortiSandbox threat-analysis product line, affecting on-premises 4.4.x and 5.0.x releases as well as the FortiSandbox Cloud and PaaS offerings. An unauthenticated attacker can trigger it remotely by sending crafted HTTP requests to the affected FortiSandbox web service, bypassing access controls without needing credentials or user interaction. A successful attacker gains access to sensitive information handled by the appliance; Fortinet's critical 9.9 CVSS score also reflects a scope change with a high availability-impact component, so defenders should treat the practical impact as potentially broader than simple information disclosure. Any organization running affected versions of FortiSandbox, FortiSandbox Cloud, or FortiSandbox PaaS is in scope, though the product's enterprise appliance/cloud deployment model means the affected population is far smaller than endpoint or firewall software. There is no evidence of exploitation so far: the flaw is not in CISA KEV, has no known public proof-of-concept, and EPSS assigns roughly a 0.2% probability of exploitation within 30 days.

Do: Upgrade all FortiSandbox deployments to a fixed release outside the affected ranges — later than 5.0.5 on the 5.0 branch, later than 4.4.8 on the 4.4 branch, and later than 5.0.5 for Cloud and PaaS — following Fortinet's PSIRT advisory. Until patched, restrict HTTP/HTTPS management access to the appliance to trusted management networks or VPN, since the flaw is reachable without authentication. Monitor Fortinet's advisory and the CISA KEV catalog for updates, given the critical severity score.

9.9<1%
  • Fortinet FortiSandbox 5.0.0 through 5.0.5
  • Fortinet FortiSandbox 4.4.0 through 4.4.8
  • Fortinet FortiSandbox Cloud 5.0.4 through 5.0.5
  • +1 more
moderatelikely on the order of several thousand to ~10,000 deployed FortiSandbox appliances/instances worldwide, with only a smaller subset exposing the vulnerable web…