CVE-2026-25089
Description
Fortinet FortiSandbox is vulnerable to OS command injection via crafted HTTP requests, allowing unauthenticated attackers to execute arbitrary commands.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Fortinet FortiSandbox is vulnerable to OS command injection via crafted HTTP requests, allowing unauthenticated attackers to execute arbitrary commands.
Vulnerability
An improper neutralization of special elements used in an OS command vulnerability (CWE-78) exists in the WEB UI of FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS. This affects FortiSandbox versions 5.0.0 through 5.0.5, 4.4.0 through 4.4.8, and all versions of 4.2. It also affects FortiSandbox Cloud and PaaS versions 5.0.4 through 5.0.5. The vulnerability is triggered by specifically crafted HTTP requests [1].
Exploitation
An unauthenticated attacker can exploit this vulnerability by sending specifically crafted HTTP requests to the affected devices. The vulnerability lies within the start vnc feature, which does not properly neutralize special elements used in OS commands, allowing for command injection [1].
Impact
Successful exploitation allows an unauthenticated attacker to execute unauthorized commands on the affected FortiSandbox instances. This could lead to a compromise of the system's integrity and confidentiality, depending on the commands executed.
Mitigation
Fortinet has released patches for the affected versions. Users should upgrade to FortiSandbox 5.0.6 or above, FortiSandbox 4.4.9 or above, or FortiSandbox Cloud 5.0.6 or above. FortiSandbox versions 5.2 and FortiSandbox Cloud 5.2 are not affected [1].
AI Insight generated on Jun 9, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: 5.0.0 through 5.0.5, 4.4.0 through 4.4.8, 4.2, 5.0.4 through 5.0.5, 5.0.4 through 5.0.5
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1News mentions
2- Fortinet: Critical Command Injection and Other Flaws Disclosed TogetherVypr Intelligence · Jun 9, 2026
- Fortinet FortiSandbox Vulnerability Allows Attackers to Execute Unauthorized CommandsCyber Security News · Jun 9, 2026