CVE-2026-39812
Received
Received - Intake
Cross-Site Scripting in Fortinet FortiSandbox Enables Code Execution
Publication date: 2026-04-14
Last updated on: 2026-04-21
Assigner: Fortinet, Inc.
Description
Description
A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox PaaS 5.0.0 through 5.0.5, FortiSandbox PaaS 4.4.0 through 4.4.8, FortiSandbox PaaS 4.2 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| fortinet | fortisandbox | From 4.2.0 (inc) to 4.2.8 (inc) |
| fortinet | fortisandbox_cloud | 5.0.4 |
| fortinet | fortisandbox | From 4.4.0 (inc) to 4.4.9 (exc) |
| fortinet | fortisandbox | From 5.0.0 (inc) to 5.0.6 (exc) |
| fortinet | fortisandbox_cloud | 5.0.5 |
| fortinet | fortisandbox_cloud | From 23.3.4329 (inc) to 24.1.4436 (inc) |
| fortinet | fortisandbox_cloud | From 22.2.4134 (inc) to 23.1.4260 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-79 | The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. |