A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>
References
| Link | Resource |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-26-100 | Vendor Advisory |
| https://github.com/samu-delucas/CVE-2026-39808 |
Configurations
History
22 Apr 2026, 14:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
20 Apr 2026, 19:11
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://fortiguard.fortinet.com/psirt/FG-IR-26-100 - Vendor Advisory | |
| CPE | cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:* | |
| First Time |
Fortinet
Fortinet fortisandbox |
14 Apr 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-14 16:16
Updated : 2026-04-22 14:17
NVD link : CVE-2026-39808
Mitre link : CVE-2026-39808
CVE.ORG link : CVE-2026-39808
JSON object : View
Products Affected
fortinet
- fortisandbox
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
