An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox Cloud 5.0.4 may allow a privileged attacker with super-admin profile and CLI access to execute unauthorized code or commands via crafted HTTP requests.
Advisories
No advisories yet.
Fixes
Solution
Fortinet remediated this issue in FortiSandbox Cloud version 5.0.5 and hence customers do not need to perform any action.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-26-096 |
|
History
Tue, 10 Mar 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox Cloud 5.0.4 may allow a privileged attacker with super-admin profile and CLI access to execute unauthorized code or commands via crafted HTTP requests. | |
| First Time appeared |
Fortinet
Fortinet fortisandboxcloud |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:fortinet:fortisandboxcloud:5.0.4:*:*:*:*:*:*:* | |
| Vendors & Products |
Fortinet
Fortinet fortisandboxcloud |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2026-03-10T16:44:06.991Z
Reserved: 2026-02-06T08:48:58.542Z
Link: CVE-2026-25836
No data.
Status : Received
Published: 2026-03-10T18:18:38.090
Modified: 2026-03-10T18:18:38.090
Link: CVE-2026-25836
No data.
OpenCVE Enrichment
No data.
Weaknesses