The vulnerability allows an attacker to bypass authentication.
| Vendor | Product | Versions |
|---|---|---|
| fortinet | fortisandbox | 5.0.0, 4.4.0, 24.1, 23.4, 5.0.4, FortiSandbox 4.4.0 - 4.4.8, FortiSandbox 5.0.0 - 5.0.5, FortiAnalyzer Cloud 7.6.2 - 7.6.4, FortiManager Cloud 7.6.2 - 7.6.4, FortiDDoS-F 7.2.1 - 7.2.2, 4.4.9 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| fortinet | fortisandbox cloud | mitre_affected | 90% |
Added affected version 4.4.9 and updated patch availability to 5.0.6, along with new tags for path traversal and JRPC API.
Updated description to specify that CVE-2026-39813 allows an attacker to bypass authentication.
Updated description to specify the vulnerability is in the FortiSandbox JRPC API and marked exploit availability as true.
Updated description with details on exploitation and added 'command injection' as a new tag.
Updated affected versions to include 5.0.6 and 4.4.9, added patch available version 5.0.6, and marked the vulnerability as actively exploited.
Initial creation