Fortinet Patches CVE-2026-26084 Flaw Letting Unauthenticated Users Access FortiSandbox Data
Fortinet disclosed CVE-2026-26084 on September 8, 2026, a high-severity information disclosure vulnerability rated 8.9 affecting multiple versions of FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS. The flaw, classified as CWE-284 (improper access control), allows unauthenticated attackers to send crafted HTTP requests and retrieve sensitive device data such as configuration, sample metadata, and analysis logs. The vulnerability stems from the web interface failing to validate requests against an authorized session before returning data, with exposure also depending on how NAT rules are configured at the network edge. Fortinet's internal product security team discovered the flaw, and no exploitation in the wild has been reported. Users are advised to upgrade to FortiSandbox 4.4.9 or 5.0.6 and ensure management interfaces are not reachable from untrusted networks.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in