216.73.216.233

CVE-2026-25089

· Published 09/06/2026 16:16 · Modified 09/06/2026 19:30

Labels: CVE-2026-25089 2026-06-09CVE-2026-25089CWE-78[email protected]

Essential information

Published
09/06/2026 16:16
Modified
09/06/2026 19:30
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
fortinet / fortisandbox cpe:2.3:a:fortinet:fortisandbox:5.0.0-5.0.5:*:*:*:*:*:*:*
fortinet / fortisandbox cpe:2.3:a:fortinet:fortisandbox:4.4.0-4.4.8:*:*:*:*:*:*:*
fortinet / fortisandbox cpe:2.3:a:fortinet:fortisandbox:4.2:*:*:*:*:*:*:*
fortinet / fortisandbox cloud cpe:2.3:a:fortinet:fortisandbox_cloud:5.0.4-5.0.5:*:*:*:*:*:*:*
fortinet / fortisandbox paas cpe:2.3:a:fortinet:fortisandbox_paas:5.0.4-5.0.5:*:*:*:*:*:*:*

References