A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests
| Vendor | Product | Versions |
|---|---|---|
| fortinet | fortisandbox | 5.0.0, 4.4.0, 4.2.1, 5.0.4, 5.0.4, 5.0.5, 4.4.8, 4.2 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| fortinet | fortisandbox cloud | mitre_affected | 90% |
| fortinet | fortisandbox paas | mitre_affected | 90% |
| fortinet | fortisandbox | cert_advisory | 90% |
| fortinet | fortisandbox_cloud | cve_cpe | 95% |
| fortinet | fortisandbox_paas | cve_cpe | 95% |
Updated affected versions to include complete ranges (5.0.5, 4.4.8, 4.2 instead of incomplete list) and added patch version 5.0.6 for versions 5.0.x and FortiSandbox Cloud/PaaS
Updated description with technical details on the "start VNC" feature and JSON payload exploitation, increased CVSS score to 9.8, added affected versions 4.2.x, and updated patch information to 4.4.9+ and 5.0.6+.
Updated description to specify that CVE-2026-25089 allows arbitrary command execution and noted that it was patched in June 2026.
Updated CVSS score to 9.8, added affected version 4.4.9, marked exploit as available, and confirmed patch available for 4.4.9.
Updated patch version to 5.0.6, added new affected versions, and marked the vulnerability as actively exploited.
Updated affected versions to include 4.4.9, confirmed patch available as 5.0.6, and marked exploit as available and actively exploited.
Added affected version 5.2 and updated patch available to 5.0.6.
Initial creation