CVE-2026-26083

critical
Published 2026-05-12 · Modified 2026-05-15
CVSS v3
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
VIR risk
9.8

Description

A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 through 5.0.5, FortiSandbox PaaS 23.4 all versions, FortiSandbox PaaS 23.3 all versions, FortiSandbox PaaS 23.1 all versions, FortiSandbox PaaS 22.2 all versions, FortiSandbox PaaS 22.1 all versions, FortiSandbox PaaS 21.4 all versions, FortiSandbox PaaS 21.3 all versions, FortiSandbox PaaS 5.0.0 through 5.0.1, FortiSandbox PaaS 4.4.5 through 4.4.8 may allow an unauthenticated attacker to execute unauthorized code or commands via HTTP requests.

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@fortinet.com — https://fortiguard.fortinet.com/psirt/FG-IR-26-136

Application impact

VendorProductVersionsFixed
fortinetfortisandbox{"startIncluding":"4.4.0","endExcluding":"4.4.9"}4.4.9
fortinetfortisandbox_cloud{"startIncluding":"5.0.2","endExcluding":"5.0.6"}5.0.6
fortinetfortisandbox_cloud24.1.4436
fortinetfortisandbox_paas{"startIncluding":"4.4.5","endExcluding":"4.4.9"}4.4.9

References

CWEs

CWE-862

Verify integrity in audit chain (admin only). AS-IS.