CVE-2026-26084
Awaiting Analysis
Awaiting Analysis - Queue
Improper Access Control in Fortinet FortiSandbox
Vulnerability report for CVE-2026-26084, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-08
Last updated on: 2026-09-08
Assigner: Fortinet, Inc.
Description
Description
A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| fortinet | fortisandbox | From 5.0.0 (inc) to 5.0.5 (inc) |
| fortinet | fortisandbox | From 4.4.0 (inc) to 4.4.8 (inc) |
| fortinet | fortisandbox_cloud | From 5.0.4 (inc) to 5.0.5 (inc) |
| fortinet | fortisandbox_paas | From 5.0.4 (inc) to 5.0.5 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |