CVE-2026-27316
Received
Received - Intake
Insufficiently Protected Credentials in Fortinet FortiSandbox Allow LDAP Exposure
Publication date: 2026-04-14
Last updated on: 2026-04-22
Assigner: Fortinet, Inc.
Description
Description
A insufficiently protected credentials vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4 all versions, FortiSandbox PaaS 5.0.1 through 5.0.5 may allow an authenticathed administrator to read LDAP server credentials via client-side inspection.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| fortinet | fortisandbox_cloud | 5.0.4 |
| fortinet | fortisandbox_cloud | 5.0.5 |
| fortinet | fortisandbox | From 4.4.0 (inc) to 5.0.6 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-522 | The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. |