CRITICAL

CVE-2026-39808

Fortinet Fortisandbox 2026-04-14 CVSS v3.1
CVSS
9.8
KEV

Description

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

Summary dbcve.org

A command injection vulnerability in FortiSandbox versions 4.4.0 through 4.4.8 allows attackers to execute unauthorized OS commands due to improper neutralization of special elements in input. This critical flaw (CVSS 9.8) enables complete system compromise through malformed requests.

Mitigation

Upgrade FortiSandbox to the latest available version beyond 4.4.8. Apply network segmentation and restrict administrative access to minimize exposure while patching.

Proof of Concept

Weakness (CWE)

CWE-78 OS Command Injection

EPSS Score

92.82%
Probability of exploitation in next 30 days
99.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE