CVE-2026-25089

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox

Severity
Critical 9.1
CVSS 3.1
Exploited
Yes — in CISA KEV
Added Jul 16, 2026
EPSS
0.698
99.3th percentile
Discovered by
Not disclosed
Published
Jun 9, 2026
Assigned by fortinet

Description

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests

Weakness: CWE-78

Affected products

Vendor Product Category Matched by
Fortinet FortiSandbox Threat Detection & Sandbox cna-assigner
Vendor-reported affected versions (3)
  • Fortinet · FortiSandbox
  • Fortinet · FortiSandbox Cloud
  • Fortinet · FortiSandbox PaaS

Vendor remediation

Upgrade to upcoming FortiSandbox version 5.2.0 or above Upgrade to FortiSandbox version 5.0.6 or above Upgrade to FortiSandbox version 4.4.9 or above Upgrade to upcoming FortiSandbox PaaS version 5.2.0 or above Upgrade to FortiSandbox PaaS version 5.0.6 or above Fortinet remediated this issue in FortiSandbox Cloud version 5.2.0 (not released) and hence customers do not need to perform any action. Fortinet remediated this issue in FortiSandbox Cloud version 5.0.6 (not released) and hence customers do not need to perform any action.