CVE-2026-39813

A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially crafted HTTP req

Severity
Critical 9.1
CVSS 3.1
Remote · no auth what this means
Exploited
Not listed
EPSS
0.007
52.3th percentile
Discovered by
Vendor
Vendor advisory field
Published
Apr 14, 2026
Assigned by fortinet

Description

A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially crafted HTTP requests.

Weakness: CWE-24

Affected products

Vendor Product Category Matched by
Fortinet FortiSandbox Threat Detection & Sandbox cna-assigner
Vendor-reported products (2)
  • Fortinet · FortiSandbox
  • Fortinet · FortiSandbox Cloud

Credit

Internally discovered and reported by Loic Pantano of Fortinet PSIRT

Vendor remediation

Upgrade to upcoming FortiSandbox version 5.2.0 or above Upgrade to FortiSandbox version 5.0.6 or above Upgrade to FortiSandbox version 4.4.9 or above

Something wrong here?