CVE-2026-39813
A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially crafted HTTP req
Severity
Critical 9.1
CVSS 3.1
Exploited
Not listed
EPSS
0.231
97.5th percentile
Discovered by
Not disclosed
Published
Apr 14, 2026
Assigned by fortinet
Description
A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially crafted HTTP requests.
Weakness: CWE-24
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiSandbox | Threat Detection & Sandbox | cna-assigner |
Vendor-reported affected versions (2)
- Fortinet · FortiSandbox
- Fortinet · FortiSandbox Cloud
Vendor remediation
Upgrade to upcoming FortiSandbox version 5.2.0 or above Upgrade to FortiSandbox version 5.0.6 or above Upgrade to FortiSandbox version 4.4.9 or above