A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests
References
| Link | Resource |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-26-141 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
11 Jun 2026, 21:39
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Fortinet fortisandbox Cloud
Fortinet fortisandbox Paas Fortinet fortisandbox Fortinet |
|
| References | () https://fortiguard.fortinet.com/psirt/FG-IR-26-141 - Vendor Advisory | |
| CPE | cpe:2.3:a:fortinet:fortisandbox_cloud:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisandbox_paas:*:*:*:*:*:*:*:* |
09 Jun 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-09 16:16
Updated : 2026-06-11 21:39
NVD link : CVE-2026-25089
Mitre link : CVE-2026-25089
CVE.ORG link : CVE-2026-25089
JSON object : View
Products Affected
fortinet
- fortisandbox_cloud
- fortisandbox_paas
- fortisandbox
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
