CVE-2026-39808 is an OS command injection flaw that can be exploited to execute arbitrary code or commands.
| Vendor | Product | Versions |
|---|---|---|
| fortinet | fortisandbox | 4.4.0, 23.4.4374, 23.4.4350, 23.3.4329, 23.1.4245, 22.2.4151, 22.2.4134, 22.1.4113, 21.4.4072, 21.3.4055 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| fortinet | fortisandbox paas | mitre_affected | 90% |
Updated description to clarify the nature of the vulnerability and confirmed severity as CRITICAL.
Updated description with details on unauthenticated access and exploitation via specially crafted HTTP requests, and added new relevant tags.
Updated affected versions to include 5.0.6 and provided a more detailed description of the vulnerability.
Updated description with new details and added tag for FortiSandbox PaaS.
Updated affected versions to include 4.4.9, marked exploit as available, and noted that the vulnerability is actively exploited.
Initial creation