Fortinet FortiSandbox OS Command Injection Vulnerability

Vulnerability

A vulnerability allowing OS command injection has been identified in Fortinet FortiSandbox versions 5.0.0 to 5.0.5, 4.4.0 to 4.4.8, all versions of 4.2, as well as FortiSandbox Cloud and FortiSandbox PaaS versions 5.0.4 to 5.0.5. This vulnerability allows an unauthenticated attacker to execute unauthorized commands by sending specially crafted HTTP requests.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of commands on the affected system.

Remediation

Users can upgrade Fortinet FortiSandbox to version 5.0.6 or 4.4.9, depending on their current version. FortiSandbox Cloud and FortiSandbox PaaS users should also upgrade to version 5.0.6.

Added: Jun 9, 2026, 4:27 PM
Updated: Jun 9, 2026, 4:27 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
7.5
exploitability
7.0
remediation
7.7
relevance
9.4
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.