CVE-2026-26083
Analyzed
Analyzed - Analysis Complete
BaseFortify
Publication date: 2026-05-12
Last updated on: 2026-05-15
Assigner: Fortinet, Inc.
Description
Description
A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 through 5.0.5, FortiSandbox PaaS 23.4 all versions, FortiSandbox PaaS 23.3 all versions, FortiSandbox PaaS 23.1 all versions, FortiSandbox PaaS 22.2 all versions, FortiSandbox PaaS 22.1 all versions, FortiSandbox PaaS 21.4 all versions, FortiSandbox PaaS 21.3 all versions, FortiSandbox PaaS 5.0.0 through 5.0.1, FortiSandbox PaaS 4.4.5 through 4.4.8 may allow an unauthenticated attacker to execute unauthorized code or commands via HTTP requests.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| fortinet | fortisandbox | From 4.4.0 (inc) to 4.4.9 (exc) |
| fortinet | fortisandbox | From 5.0.0 (inc) to 5.0.2 (exc) |
| fortinet | fortisandbox_cloud | From 5.0.2 (inc) to 5.0.6 (exc) |
| fortinet | fortisandbox_cloud | From 23.1.4245 (inc) to 23.4.4374 (inc) |
| fortinet | fortisandbox_cloud | 24.1.4436 |
| fortinet | fortisandbox_paas | From 4.4.5 (inc) to 4.4.9 (exc) |
| fortinet | fortisandbox_paas | From 5.0.0 (inc) to 5.0.2 (exc) |
| fortinet | fortisandbox_paas | From 21.3.4055 (inc) to 23.4.4374 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |
Attack-Flow Graph
Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70