Project Subscriptions
No advisories yet.
Solution
Upgrade to upcoming FortiSandbox version 5.2.0 or above Upgrade to FortiSandbox version 5.0.6 or above Upgrade to FortiSandbox version 4.4.9 or above
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-26-112 |
|
Wed, 24 Jun 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Directory Traversal Leading to Privilege Escalation in FortiSandbox |
Wed, 24 Jun 2026 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Directory Traversal Leading to Privilege Escalation in FortiSandbox |
Wed, 24 Jun 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Path Traversal Allowing Privilege Escalation via Specially Crafted HTTP Requests in FortiSandbox |
Wed, 24 Jun 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Path Traversal Allowing Privilege Escalation via Specially Crafted HTTP Requests in FortiSandbox |
Tue, 23 Jun 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | FortiSandbox Path Traversal Enables Privilege Escalation via HTTP Requests |
Thu, 18 Jun 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | FortiSandbox Path Traversal Enables Privilege Escalation via HTTP Requests |
Thu, 18 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via <insert attack vector here> | A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially crafted HTTP requests. |
| Title | Path Traversal Exploitation Allowing Privilege Escalation in Fortinet FortiSandbox |
Wed, 17 Jun 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Path Traversal Exploitation Allowing Privilege Escalation in Fortinet FortiSandbox |
Tue, 16 Jun 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Privilege Escalation via Path Traversal in FortiSandbox |
Mon, 20 Apr 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:* |
Wed, 15 Apr 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Privilege Escalation via Path Traversal in FortiSandbox |
Tue, 14 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 14 Apr 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via <insert attack vector here> | |
| First Time appeared |
Fortinet
Fortinet fortisandbox Fortinet fortisandboxcloud |
|
| Weaknesses | CWE-24 | |
| CPEs | cpe:2.3:a:fortinet:fortisandbox:4.4.0:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisandbox:4.4.1:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisandbox:4.4.2:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisandbox:4.4.3:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisandbox:4.4.4:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisandbox:4.4.5:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisandbox:4.4.6:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisandbox:4.4.7:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisandbox:4.4.8:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisandbox:5.0.0:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisandbox:5.0.1:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisandbox:5.0.2:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisandbox:5.0.3:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisandbox:5.0.4:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisandbox:5.0.5:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisandboxcloud:23.4:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisandboxcloud:24.1:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisandboxcloud:5.0.4:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisandboxcloud:5.0.5:*:*:*:*:*:*:* |
|
| Vendors & Products |
Fortinet
Fortinet fortisandbox Fortinet fortisandboxcloud |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2026-06-18T09:01:15.877Z
Reserved: 2026-04-07T15:24:13.846Z
Link: CVE-2026-39813
Updated: 2026-04-14T16:36:55.508Z
Status : Analyzed
Published: 2026-04-14T16:16:45.680
Modified: 2026-04-20T19:11:30.867
Link: CVE-2026-39813
No data.
OpenCVE Enrichment
Updated: 2026-06-24T12:45:04Z