HarborGuard / CVE
Back to search
CRITICALCVE-2026-26083Published Modified CNA fortinet

CVE-2026-26083: A missing authorization vulnerability in Fortinet FortiSandbox 5

A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 through 5.0.5, FortiSandbox PaaS 23.4 all versions, FortiSandbox PaaS 23.3 all versions, FortiSandbox PaaS 23.1 all versions, FortiSandbox PaaS 22.2 all versions, FortiSandbox PaaS 22.1 all versions, FortiSandbox PaaS 21.4 all versions, FortiSandbox PaaS 21.3 all versions, FortiSandbox PaaS 5.0.0 through 5.0.1, FortiSandbox PaaS 4.4.5 through 4.4.8 may allow an unauthenticated attacker to execute unauthorized code or commands via HTTP requests.

Metrics

CVSS v3.1
9.1
Severity
CRITICAL
Fixed in
Affected Products
3
Affected packages
  • Fortinet / FortiSandbox Cloud
    ≤ 5.0.1 · ≤ 4.4.8
  • Fortinet / FortiSandbox
    ≤ 5.0.1 · ≤ 4.4.8 · ≤ 4.2.8
  • Fortinet / FortiSandbox PaaS
    23.4.4374 · 23.4.4350 · 23.3.4329 · 23.1.4245 · 22.2.4151 · 22.2.4134
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C