A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests.
In plain language
Written by AI from the record
Fortinet FortiSandbox has a flaw that lets an attacker access confidential data just by sending web requests—so typical small businesses running it should urgently update.
Improper access control (CWE-284) in Fortinet FortiSandbox allows unauthenticated attackers to access sensitive information by sending specially crafted HTTP requests to the product’s exposed network interface.
If you're affected
Confidential data exposure
Potential data theft from sandbox
Service disruption risk
What is it
FortiSandbox is meant to safely handle and analyze suspicious content. This vulnerability is like leaving a private room door unlocked: someone can send the right kind of web request and view confidential information without logging in. Even if you don’t think you’re using “security” features, the product is still exposing a web-facing access path.
Who is affected
This matters if your business runs Fortinet FortiSandbox, FortiSandbox Cloud, or FortiSandbox PaaS in the vulnerable versions. The risk is highest when the product is reachable over the network from an attacker, because the flaw does not require login or user interaction. Reachability is the key gate: it’s a concern when the HTTP interface can be reached from outside your network.
How urgent is it
This is a RED issue because attackers can directly reach it over the network and read confidential data without authentication. Even though there’s no clear public claim of active exploitation for this exact CVE, the weakness is straightforward and the vendor has issued specific fixed versions. Treat it as a priority upgrade on your next change window, and restrict exposure immediately if internet access isn’t required.
What to do — in detail
Identify exposure (inventory)
Find the FortiSandbox deployment(s): FortiSandbox, FortiSandbox Cloud, and/or FortiSandbox PaaS.
Record the exact installed version for each.
Determine whether you’re in the vulnerable range
Vulnerable FortiSandbox versions: 5.0.0 through 5.0.5, and 4.4.0 through 4.4.8.
Vulnerable FortiSandbox Cloud versions: 5.0.4 through 5.0.5.
Vulnerable FortiSandbox PaaS versions: 5.0.4 through 5.0.5.
Upgrade to a fixed version (use the exact version guidance below)
FortiSandbox: upgrade to 5.0.6 or above (or 5.2.0 or above, per the vendor’s combined guidance).
FortiSandbox 4.4: upgrade to 4.4.9 or above.
FortiSandbox Cloud: upgrade to 5.0.6 or above.
FortiSandbox PaaS: upgrade to 5.2.0 or above.
Validate after patching
Confirm the upgrade succeeded and the service is running as expected.
Verify that the web service is not broadly exposed to the internet unless explicitly required.
If you have access to logs, review for unusual bursts of HTTP requests to the FortiSandbox endpoints around the time of patching.
Temporary workaround if you cannot patch immediately
Restrict network access to FortiSandbox so that only approved internal systems (or specific IPs) can reach the HTTP interface.
If FortiSandbox must remain reachable, place it behind stricter firewall rules and rate-limiting as your environment allows.
What to monitor
Continue monitoring web request logs for repeated failed/atypical requests from unusual sources.
Confirm no recurrence after the upgrade.
CISA KEV note
This CVE is not listed in the CISA KEV feed per the provided findings.
Technical context
CVE-2026-26084 is an improper access control issue (CWE-284) affecting Fortinet FortiSandbox components (fortisandbox, fortisandbox cloud, fortisandbox paas) in specific version ranges. The mechanism is unauthenticated access control failure: an attacker can send crafted HTTP requests to the exposed product and view sensitive information. Findings indicate no public exploit code is known and no clear dated reporting of exploitation in the press for this specific CVE; however, press attention is rising due to broader Fortinet vulnerability roundup activity. KEV listing was not found, so there is no CISA-confirmed exploitation signal here. The reported predicted likelihood is low and flat, but the verdict remains RED because the issue is reachable without authentication and the vendor has provided clear fixed releases.
This is a general assessment based on public vulnerability data. It does not account for your specific infrastructure — when in doubt, consult a security specialist.