Vulnerabilities (CVE)

Filtered by vendor Fortinet Subscribe
Filtered by product Fortisandbox Cloud
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-25836 1 Fortinet 1 Fortisandbox Cloud 2026-03-18 N/A 7.2 HIGH
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox Cloud 5.0.4 may allow a privileged attacker with super-admin profile and CLI access to execute unauthorized code or commands via crafted HTTP requests.
CVE-2025-53679 1 Fortinet 2 Fortisandbox, Fortisandbox Cloud 2026-02-05 N/A 7.2 HIGH
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions, FortiSandbox Cloud 24.1, FortiSandbox Cloud 23 all versions allows a remote privileged attacker to execute unauthorized code or commands via crafted HTTP or HTTPS requests.
CVE-2024-54026 1 Fortinet 2 Fortisandbox, Fortisandbox Cloud 2026-01-14 N/A 4.3 MEDIUM
An improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiSandbox 4.4.0 through 4.4.6, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all versions, FortiSandbox Cloud 24.1 allows attacker to execute unauthorized code or commands via specifically crafted HTTP requests.