Medium severity4.8NVD Advisory· Published Apr 14, 2026· Updated Apr 21, 2026
CVE-2026-39812
CVE-2026-39812
Description
A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox PaaS 5.0.0 through 5.0.5, FortiSandbox PaaS 4.4.0 through 4.4.8, FortiSandbox PaaS 4.2 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>
Affected products
4cpe:2.3:a:fortinet:fortisandbox_cloud:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:fortinet:fortisandbox_cloud:*:*:*:*:*:*:*:*range: >=22.2.4134,<=23.1.4260
- cpe:2.3:a:fortinet:fortisandbox_cloud:5.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortisandbox_cloud:5.0.5:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- fortiguard.fortinet.com/psirt/FG-IR-26-110nvdVendor Advisory
News mentions
1- Fortinet warns of critical RCE flaws in FortiSandbox and FortiAuthenticatorBleepingComputer · May 12, 2026