CVE-2026-39813

Published Apr 14, 2026

Last updated a month ago

CVSS critical 9.8
FortiSandbox

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-39813 is a path traversal vulnerability identified in Fortinet FortiSandbox. This flaw, specifically a '../filedir' path traversal, exists within the FortiSandbox JRPC API due to insufficient input validation. Exploitation of this vulnerability allows an unauthenticated attacker to bypass authentication and potentially escalate privileges on the system by sending specially crafted HTTP requests. The affected versions include FortiSandbox 4.4.0 through 4.4.8 and FortiSandbox 5.0.0 through 5.0.5.

Description
A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially crafted HTTP requests.
Source
psirt@fortinet.com
NVD status
Modified
Products
fortisandbox

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

psirt@fortinet.com
CWE-24

Social media

Hype score
Not currently trending
  1. ⚠️ استغلال فعلي لثلاث ثغرات حرجة في FortiSandbox تتيح تجاوز المصادقة وحقن أوامر نظام دون أي تدخل من المستخدم المعرّفات : CVE-2026-39813, CVE-2026-39808, CVE-2026-25089 درجة الخطور

    @KasperskyDev

    27 Jun 2026

    88 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. ⚠️ Vulnerabilidades en productos Fortinet ❗ CVE-2026-39815 ❗ CVE-2026-39813 ❗ CVE-2026-39808 ➡️ Más info: https://t.co/ECQsWx3mLA https://t.co/eCsaTqaIiG

    @CERTpy

    26 Jun 2026

    236 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  3. FortiSandbox の脆弱性 CVE-2026-39813/39808/25089:実環境での悪用を観測 https://t.co/0OOmXVc2eT FortiSandbox

    @iototsecnews

    23 Jun 2026

    128 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. FortiSandbox 3 CVE in exploitation ITW: CVE-2026-39813 (CVSS 9.8, auth bypass JRPC API) + CVE-2026-39808 (OS cmd injection, PoC pubblico aprile). FortiSandbox = verdict-engine di FortiGate/FortiMail/FortiWeb. Fix: 5.0.6/4.4.9 #Fortinet

    @trinacriatech

    22 Jun 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Attackers exploited CVE-2026-39808 and CVE-2026-39813 to compromise FortiSandbox systems and move laterally within connected networks. This campaign demonstrates how security infrastructure becomes a pivot point for broader network access. Runtime segmentation helps contain such

    @aviatrixtrc

    18 Jun 2026

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. FortiSandbox: 3 CVEs exploited Three FortiSandbox flaws under active exploitation, all already patched: •CVE-2026-39813 (9.1) auth bypass •CVE-2026-39808 (9.1) OS command injection •CVE-2026-25089 (9.1) unauth command execution (Web UI) It feeds verdicts to your whole

    @ElusivePrivacy

    18 Jun 2026

    64 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 【FortiSandboxの複数重大脆弱性に悪用試行】 Fortinet FortiSandboxで、CVE-2026-39813、CVE-2026-39808、CVE-2026-25089の悪用試行が報告されています。 認証バイパスやOSコマンドインジェクションにつながる脆弱性で、FortiSandb

    @01ra66it

    17 Jun 2026

    254 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Attackers are exploiting patched Fortinet FortiSandbox flaws, including CVE-2026-39808 and CVE-2026-39813, with active activity seen across multiple countries and risk to connected Fortinet devices. #Fortinet #FortiSandbox #Japan https://t.co/aeTTmvSm5b

    @TweetThreatNews

    17 Jun 2026

    138 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Intel Report [CRITICAL] - Three critical vulnerabilities in Fortinet FortiSandbox products (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089), each rated CVSS 9.1, are under active exploitation by unknown threat actors as of mid-June 2026. The... https://t.co/83LRIRhJvs

    @EnigmaGlobalSW

    17 Jun 2026

    49 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Fortinet FortiSandbox: CVE-2026-39808 und CVE-2026-39813 werden aktiv ausgenutzt. Patches seit April verfügbar – Update jetzt! Habt ihr eure Fortinet-Geräte bereits gepatcht? #CVE #CyberSecurity #PatchManagement https://t.co/SFWvdPx6gk

    @wall_your_x

    17 Jun 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Trois failles de FortiSandbox récemment corrigées sont actuellement exploitées. Les honeypots de Defused, entreprise de renseignement sur les exploits, ont détecté des tentatives d'exploitation des CVE-2026-39808, CVE-2026-39813, et CVE-2026-25089. https://t.co/rTfx9X359h

    @cert_ist

    17 Jun 2026

    58 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. 🚨 Upozorňujeme na aktivně zneužívané zranitelnosti ve Fortinet FortiSandbox, CVE-2026-39813, CVE-2026-39808, CVE-2026-25089. Útočníci aktivně zneužívají více chyb ve FortiSandbox, přičemž CVE-2026-39813 (CVSS 9.1) představuje path traversal v JRPC API umož

    @GOVCERT_CZ

    17 Jun 2026

    540 Impressions

    2 Retweets

    5 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  13. 🚨 Fortinet FortiSandbox Alert Attackers are exploiting 3 critical flaws: 🔴 CVE-2026-39813 🔴 CVE-2026-39808 🔴 CVE-2026-25089 Patch now, restrict management access, and review logs. https://t.co/N121ehAPaM #CyberSecurity #Fortinet #CVE #Vulert

    @vulert_official

    17 Jun 2026

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. Fortinet FortiSandboxの重大な脆弱性が攻撃に悪用される(CVE-2026-39813、CVE-2026-39808、CVE-2026-25089) | Codebook|Security News https://t.co/uEhZFFhodL

    @ohhara_shiojiri

    17 Jun 2026

    49 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  15. 🚨Fortinet FortiSandboxの重大な脆弱性が攻撃に悪用される(CVE-2026-39813、CVE-2026-39808、CVE-2026-25089) ⚽️FIFA内部システムにバグ、W杯のテレビ配信を自由に改変できる状態に 〜サイバーアラート6月17日〜 https://t.c

    @MachinaRecord

    17 Jun 2026

    200 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. Fortinet reporta tres vulnerabilidades críticas en FortiSandbox explotadas activamente. CVE-2026-39813, CVE-2026-39808 y CVE-2026-25089 permiten ejecución remota de código. Parches disponibles, actualiza ya. https://t.co/cMe9dZVeH6

    @TheVortiq

    16 Jun 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. Attackers chained CVE-2026-39813 and CVE-2026-39808 to compromise FortiSandbox systems, using path traversal for authentication bypass then command injection for privilege escalation. Lateral movement followed, highlighting how security appliance compromise can expose entire

    @aviatrixtrc

    16 Jun 2026

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. Attackers are exploiting FortiSandbox vulnerabilities: Attackers have been spotted exploiting three vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) in FortiSandbox, a platform that other Fortinet security products depend on for threat… https://t.co/55j3T5laWe h

    @shah_sheikh

    16 Jun 2026

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. 🔐 Exploit watch: The Hacker News reports active exploitation of Fortinet FortiSandbox flaws CVE-2026-39813, CVE-2026-39808 and CVE-2026-25089 over the past 24 hours, citing Defused Cyber. #Fortinet #Cybersecurity https://t.co/fiN9z90ZOl

    @Divinmentis

    16 Jun 2026

    67 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  20. Exploitation attempts detected against Fortinet #FortiSandbox targeting CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089 (all CVSS 9.1). CVE-2026-39813 shows no prior #exploitation evidence, suggesting recent availability of working exploits. https://t.co/ZOvLG4wBNH

    @MeridianEU

    16 Jun 2026

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. CVE Alert: Fortinet FortiSandbox Attackers are reportedly exploiting three Fortinet FortiSandbox vulnerabilities: • CVE-2026-39813 | CVSS 9.1 • CVE-2026-39808 | CVSS 9.1 • CVE-2026-25089 | CVSS 9.1 The flaws include path traversal and OS command injection issues that cou

    @CloneSystemsInc

    16 Jun 2026

    60 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. Cyber attackers are exploiting three critical vulnerabilities in Fortinet's FortiSandbox appliances: CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089. These flaws allow unauthenticated access and command execution via crafted HTTP requests. Fortinet has released patches, but ht

    @dailytechonx

    16 Jun 2026

    41 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. Active attacks target critical Fortinet FortiSandbox flaws, including CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089, enabling privilege escalation and RCE without user interaction. #Fortinet #FortiSandbox #CVE2026 https://t.co/mYbEyw8GhX

    @TweetThreatNews

    16 Jun 2026

    136 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  24. 🚨We are observing exploitation of multiple Fortinet FortiSandbox vulnerabilities during the past 24 hours, including: CVE-2026-39813 (no previous recorded exploitation) CVE-2026-39808 CVE-2026-25089 (vibecoded, likely faulty exploit) Per our research a working exploit for

    @DefusedCyber

    15 Jun 2026

    5401 Impressions

    15 Retweets

    51 Likes

    16 Bookmarks

    2 Replies

    1 Quote

Configurations

References

Sources include official advisories and independent security research.