A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>
References
| Link | Resource |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-26-100 | Vendor Advisory |
| https://github.com/samu-delucas/CVE-2026-39808 | Exploit Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-39808 | US Government Resource |
Configurations
History
16 Jul 2026, 19:05
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/samu-delucas/CVE-2026-39808 - Exploit, Third Party Advisory | |
| References | () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-39808 - US Government Resource |
16 Jul 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
22 Apr 2026, 14:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
20 Apr 2026, 19:11
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://fortiguard.fortinet.com/psirt/FG-IR-26-100 - Vendor Advisory | |
| CPE | cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:* | |
| First Time |
Fortinet
Fortinet fortisandbox |
14 Apr 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-14 16:16
Updated : 2026-07-17 05:16
NVD link : CVE-2026-39808
Mitre link : CVE-2026-39808
CVE.ORG link : CVE-2026-39808
JSON object : View
Products Affected
fortinet
- fortisandbox
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
