Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2856 articles · 164136 vulns · 37/41 feeds (7d)
← Back to list
9.1
CVE-2026-39813KEVEXPLOITEDPATCHED
fortinet · fortisandbox

CVE-2026-39813: A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.

Description

The vulnerability allows an attacker to bypass authentication.

Affected Products

VendorProductVersions
fortinetfortisandbox5.0.0, 4.4.0, 24.1, 23.4, 5.0.4, FortiSandbox 4.4.0 - 4.4.8, FortiSandbox 5.0.0 - 5.0.5, FortiAnalyzer Cloud 7.6.2 - 7.6.4, FortiManager Cloud 7.6.2 - 7.6.4, FortiDDoS-F 7.2.1 - 7.2.2, 4.4.9

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
fortinetfortisandbox cloudmitre_affected90%

References

  • https://fortiguard.fortinet.com/psirt/FG-IR-26-112

Related News (12 articles)

Tier D
Heise Security1h ago
Angriffe auf FortiSandbox-Schwachstellen
→ No new info (linked only)
Tier D
SecurityWeek6h ago
3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker Crosshairs
→ No new info (linked only)
Tier D
The Hacker News1d ago
Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week
→ No new info (linked only)
Tier D
BleepingComputer1d ago
Critical Fortinet FortiSandbox flaws now exploited in attacks
→ No new info (linked only)
Tier D
The Hacker News57d ago
⚡ Weekly Recap: Vercel Hack, Push Fraud, QEMU Abused, New Android RATs Emerge & More
→ No new info (linked only)
Tier D
Help Net Security59d ago
Week in review: Acrobat Reader flaw exploited, Claude Mythos offensive capabilities and limits
→ No new info (linked only)
Tier D
Help Net Security62d ago
Fortinet fixes critical FortiSandbox vulnerabilities (CVE-2026-39813, CVE-2026-39808)
→ No new info (linked only)
Tier D
SecurityWeek63d ago
Fortinet Patches Critical FortiSandbox Vulnerabilities
→ No new info (linked only)
Tier D
Heise Security63d ago
Fortinet stopft 18 Sicherheitslecks
→ No new info (linked only)
Tier B
CCCS Canada63d ago
Fortinet security advisory (AV26-351)
→ No new info (linked only)
Tier C
VulDB63d ago
CVE-2026-39813 | Fortinet FortiSandbox/FortiSandbox Cloud up to 4.4.8/5.0.5 /filedir path traversal (FG-IR-26-112)
→ No new info (linked only)
Tier A
Fortinet PSIRT64d ago
Unauthenticated Authentication bypass and Privilege escalation in FortiSandbox
→ No new info (linked only)
CVSS 3.19.1 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
5.0.6
CWECWE-24, CWE-77, CWE-287, CWE-269, CWE-122, CWE-89
PublishedApr 14, 2026
Last enriched56m agov6
Tags
os command injectionauthentication bypassprivilege escalationheap-based buffer overflowsql injectionfortinetcritical vulnerabilitycommand injectionpath traversalJRPC API
Trending Score149🔥
Source articles12
Independent8
Info Completeness12/14
Missing: epss, iocs

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-39808EXPKEV
CVE-2026-39808: A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F
Trending: 153
CRITICALCVE-2026-25089EXP
CVE-2026-25089: A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F
Trending: 95
CRITICALCVE-2026-35616EXPKEV
CVE-2026-35616: A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated atta
Trending: 72
CRITICALCVE-2026-26083
CVE-2026-26083: A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, Fo
Trending: 67
MEDIUMCVE-2025-61624EXP
CVE-2025-61624: An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet For
Trending: 57

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 14, 2026
Added to CISA KEV
Apr 14, 2026
Discovered by ZDM
Apr 14, 2026
Updated: affectedVersions, patchAvailable, activelyExploited
Apr 14, 2026
Actively Exploited
Apr 15, 2026
Exploit Available
Apr 15, 2026
Patch Available
Apr 15, 2026
Updated: tags
Jun 16, 2026
Updated: description, exploitAvailable
Jun 16, 2026
Updated: description
Jun 17, 2026
Updated: affectedVersions, tags
Jun 17, 2026

Version History

v6
Last enriched 56m ago
v6Tier D56m ago

Added affected version 4.4.9 and updated patch availability to 5.0.6, along with new tags for path traversal and JRPC API.

affectedVersionstags
via Heise Security
v5Tier D5h ago

Updated description to specify that CVE-2026-39813 allows an attacker to bypass authentication.

description
via SecurityWeek
v4Tier D1d ago

Updated description to specify the vulnerability is in the FortiSandbox JRPC API and marked exploit availability as true.

descriptionexploitAvailable
via The Hacker News
v3Tier D1d ago

Updated description with details on exploitation and added 'command injection' as a new tag.

tags
via BleepingComputer
v2Tier A63d ago

Updated affected versions to include 5.0.6 and 4.4.9, added patch available version 5.0.6, and marked the vulnerability as actively exploited.

affectedVersionspatchAvailableactivelyExploited
via Fortinet PSIRT
v163d ago

Initial creation