Project Subscriptions
No advisories yet.
Solution
Fortinet remediated this issue in FortiSandbox Cloud version 5.0.5 and hence customers do not need to perform any action. Upgrade to FortiSandbox PaaS version 5.0.5 or above
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-26-096 |
|
Thu, 18 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | FortiSandbox OS Command Injection via Crafted HTTP Requests |
Wed, 17 Jun 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | OS Command Injection via Untrusted HTTP Requests in FortiSandbox Cloud and PaaS |
Tue, 16 Jun 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | OS Command Injection via Untrusted HTTP Requests in FortiSandbox Cloud and PaaS |
Tue, 12 May 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | OS Command Injection Vulnerability in FortiSandbox Cloud 5.0.4 |
Tue, 12 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox Cloud 5.0.4 may allow a privileged attacker with super-admin profile and CLI access to execute unauthorized code or commands via crafted HTTP requests. | An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox Cloud 5.0.4, FortiSandbox PaaS 5.0.4 may allow a privileged attacker with super-admin profile and CLI access to execute unauthorized code or commands via crafted HTTP requests. |
| First Time appeared |
Fortinet fortisandboxpaas
|
|
| CPEs | cpe:2.3:a:fortinet:fortisandboxpaas:5.0.4:*:*:*:*:*:*:* | |
| Vendors & Products |
Fortinet fortisandboxpaas
|
Wed, 15 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | OS Command Injection Vulnerability in FortiSandbox Cloud 5.0.4 |
Wed, 18 Mar 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fortinet fortisandbox Cloud
|
|
| CPEs | cpe:2.3:a:fortinet:fortisandbox_cloud:5.0.4:*:*:*:*:*:*:* | |
| Vendors & Products |
Fortinet fortisandbox Cloud
|
Tue, 10 Mar 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Mar 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox Cloud 5.0.4 may allow a privileged attacker with super-admin profile and CLI access to execute unauthorized code or commands via crafted HTTP requests. | |
| First Time appeared |
Fortinet
Fortinet fortisandboxcloud |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:fortinet:fortisandboxcloud:5.0.4:*:*:*:*:*:*:* | |
| Vendors & Products |
Fortinet
Fortinet fortisandboxcloud |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2026-05-12T16:54:09.916Z
Reserved: 2026-02-06T08:48:58.542Z
Link: CVE-2026-25836
Updated: 2026-03-10T20:30:12.938Z
Status : Modified
Published: 2026-03-10T18:18:38.090
Modified: 2026-06-17T10:25:18.817
Link: CVE-2026-25836
No data.
OpenCVE Enrichment
Updated: 2026-06-18T13:45:05Z