A insufficiently protected credentials vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4 all versions, FortiSandbox PaaS 5.0.1 through 5.0.5 may allow an authenticathed administrator to read LDAP server credentials via client-side inspection.
References
| Link | Resource |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-26-113 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
22 Apr 2026, 18:54
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:fortinet:fortisandbox_cloud:5.0.4:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisandbox_cloud:5.0.5:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:* |
|
| References | () https://fortiguard.fortinet.com/psirt/FG-IR-26-113 - Vendor Advisory | |
| First Time |
Fortinet
Fortinet fortisandbox Fortinet fortisandbox Cloud |
14 Apr 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-14 16:16
Updated : 2026-04-22 18:54
NVD link : CVE-2026-27316
Mitre link : CVE-2026-27316
CVE.ORG link : CVE-2026-27316
JSON object : View
Products Affected
fortinet
- fortisandbox
- fortisandbox_cloud
CWE
CWE-522
Insufficiently Protected Credentials
