A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox PaaS 5.0.0 through 5.0.5, FortiSandbox PaaS 4.4.0 through 4.4.8, FortiSandbox PaaS 4.2 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>
References
| Link | Resource |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-26-110 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Apr 2026, 17:12
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://fortiguard.fortinet.com/psirt/FG-IR-26-110 - Vendor Advisory | |
| CPE | cpe:2.3:a:fortinet:fortisandbox_cloud:5.0.4:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisandbox_cloud:5.0.5:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisandbox_cloud:*:*:*:*:*:*:*:* |
|
| First Time |
Fortinet
Fortinet fortisandbox Fortinet fortisandbox Cloud |
14 Apr 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-14 16:16
Updated : 2026-04-21 17:12
NVD link : CVE-2026-39812
Mitre link : CVE-2026-39812
CVE.ORG link : CVE-2026-39812
JSON object : View
Products Affected
fortinet
- fortisandbox
- fortisandbox_cloud
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
