← Back to browse · API

CVE-2026-25089

Severity
CRITICAL
CVSS
9.1
EPSS
0.73603
Risk score
82.76
CISA KEV
Yes
PoC
No
Published
2026-06-09
Modified
2026-07-17
First seen
2026-08-05
Aliases
CNVD-2026-25587, EUVD-2026-35443, GHSA-GW24-HWF5-92H2
Products
Fortinet FortiSandbox >=4.2.1,<=4.2.8, Fortinet FortiSandbox >=4.4.0,<=4.4.8, Fortinet FortiSandbox >=5.0.0,<=5.0.5, Fortinet FortiSandbox Cloud >=5.0.4,<=5.0.5, Fortinet FortiSandbox PaaS >=5.0.4,<=5.0.5, Fortinet:FortiSandbox, Fortinet:FortiSandbox 4.2.1 ≤4.2.8, Fortinet:FortiSandbox 4.4.0 ≤4.4.8, Fortinet:FortiSandbox 5.0.0 ≤5.0.5, Fortinet:FortiSandbox Cloud 5.0.4 ≤5.0.5, Fortinet:FortiSandbox PaaS 5.0.4 ≤5.0.5, fortinet:fortisandbox, fortinet:fortisandbox_cloud, fortinet:fortisandbox_paas
Sources
nvd CVE-2026-25089
cisa.gov CVE-2026-25089
cnvd CNVD-2026-25587
euvd EUVD-2026-35443

Description

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests

References