DIRAS TAKE
Urgent: this is a pre-auth access control flaw that lets unauthenticated actors retrieve sensitive data, so immediately limit network exposure to FortiSandbox HTTP services while Fortinet releases a fix.
What is CVE-2026-26084?
An unauthenticated remote attacker can access sensitive information on Fortinet FortiSandbox products using crafted HTTP requests; this is tracked as CVE-2026-26084. Affected releases include FortiSandbox 5.0.0–5.0.5, FortiSandbox PaaS 5.0.4–5.0.5, FortiSandbox Cloud 5.0.4–5.0.5, and FortiSandbox 4.2.1–4.2.8 and 4.4.0–4.4.8. The flaw requires only network access to the FortiSandbox HTTP interfaces and does not require valid credentials or user interaction.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H
Which versions of Fortinet FortiSandbox PaaS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| FortiSandbox PaaS 5.x | 5.0.4 – 5.0.5 | |
| FortiSandbox 5.x | 5.0.0 – 5.0.5 | |
| FortiSandbox 4.x | 4.4.0 – 4.4.8 | |
| FortiSandbox 4.x | 4.2.1 – 4.2.8 | |
| FortiSandbox Cloud 5.x | 5.0.4 – 5.0.5 |
Is CVE-2026-26084 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-26084
- Restrict network exposure to FortiSandbox HTTP interfaces to trusted management networks only.
- Apply strong network-level access controls or IP allowlists and place instances behind a VPN or management jump host.
- Deploy WAF rules or reverse proxies to block or inspect suspicious crafted HTTP requests targeting FortiSandbox.
- Monitor FortiSandbox access logs for unusual or repeated crafted HTTP requests and follow Fortinet guidance and updates when a patch is released.
Frequently asked questions
Is CVE-2026-26084 being actively exploited?
There are no public reports of active exploitation of CVE-2026-26084 as of 2026-09-30.
Which FortiSandbox versions are affected by CVE-2026-26084?
FortiSandbox products affected include FortiSandbox 5.0.0–5.0.5; FortiSandbox PaaS 5.0.4–5.0.5; FortiSandbox Cloud 5.0.4–5.0.5; and FortiSandbox 4.2.1–4.2.8 and 4.4.0–4.4.8.
Is there a patch for CVE-2026-26084?
No fixed versions are listed in the available information; follow Fortinet advisories and apply vendor fixes when they are published.
Does CVE-2026-26084 require authentication?
No; the vulnerability allows unauthenticated access via crafted HTTP requests to FortiSandbox HTTP interfaces.
References
- nvd.nist.gov/vuln/detail/CVE-2026-26084
- cve.org/CVERecord?id=CVE-2026-26084
- fortiguard.fortinet.com/psirt/FG-IR-26-166
- All Fortinet CVEs on CVE Radar
- CVEs published in September 2026