CRITICAL
CVE-2026-39808
CVSS
9.8
KEV
Description
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>
Summary dbcve.org
A command injection vulnerability in FortiSandbox versions 4.4.0 through 4.4.8 allows attackers to execute unauthorized OS commands due to improper neutralization of special elements in input. This critical flaw (CVSS 9.8) enables complete system compromise through malformed requests.
Mitigation
Upgrade FortiSandbox to the latest available version beyond 4.4.8. Apply network segmentation and restrict administrative access to minimize exposure while patching.
Weakness (CWE)
CWE-78
OS Command Injection
EPSS Score
92.82%
Probability of exploitation in next 30 days
99.8th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.