CVE-2026-26084: improper access control in Fortinet FortiSandbox PaaS

An unauthenticated remote attacker can access sensitive information on Fortinet FortiSandbox products using crafted HTTP requests; this is tracked as CVE-2026-26084. Affected releases include FortiSandbox 5.0.0–5.0.5, FortiSandbox PaaS 5.0.4–5.0.5, FortiSandbox Cloud 5.0.4–5.0.5, and FortiSandbox 4.2.1–4.2.8 and 4.4.0–4.4.8. The flaw requires only network access to the FortiSandbox HTTP interfaces and does not require valid credentials or user interaction.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.9CRITICAL
EPSS
0.0039
CWE
CWE-284
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: this is a pre-auth access control flaw that lets unauthenticated actors retrieve sensitive data, so immediately limit network exposure to FortiSandbox HTTP services while Fortinet releases a fix.

What is CVE-2026-26084?

An unauthenticated remote attacker can access sensitive information on Fortinet FortiSandbox products using crafted HTTP requests; this is tracked as CVE-2026-26084. Affected releases include FortiSandbox 5.0.0–5.0.5, FortiSandbox PaaS 5.0.4–5.0.5, FortiSandbox Cloud 5.0.4–5.0.5, and FortiSandbox 4.2.1–4.2.8 and 4.4.0–4.4.8. The flaw requires only network access to the FortiSandbox HTTP interfaces and does not require valid credentials or user interaction.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H

Which versions of Fortinet FortiSandbox PaaS are affected?

BRANCHAFFECTEDFIXED
FortiSandbox PaaS 5.x5.0.4 – 5.0.5
FortiSandbox 5.x5.0.0 – 5.0.5
FortiSandbox 4.x4.4.0 – 4.4.8
FortiSandbox 4.x4.2.1 – 4.2.8
FortiSandbox Cloud 5.x5.0.4 – 5.0.5

Is CVE-2026-26084 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-26084

  1. Restrict network exposure to FortiSandbox HTTP interfaces to trusted management networks only.
  2. Apply strong network-level access controls or IP allowlists and place instances behind a VPN or management jump host.
  3. Deploy WAF rules or reverse proxies to block or inspect suspicious crafted HTTP requests targeting FortiSandbox.
  4. Monitor FortiSandbox access logs for unusual or repeated crafted HTTP requests and follow Fortinet guidance and updates when a patch is released.

Frequently asked questions

Is CVE-2026-26084 being actively exploited?

There are no public reports of active exploitation of CVE-2026-26084 as of 2026-09-30.

Which FortiSandbox versions are affected by CVE-2026-26084?

FortiSandbox products affected include FortiSandbox 5.0.0–5.0.5; FortiSandbox PaaS 5.0.4–5.0.5; FortiSandbox Cloud 5.0.4–5.0.5; and FortiSandbox 4.2.1–4.2.8 and 4.4.0–4.4.8.

Is there a patch for CVE-2026-26084?

No fixed versions are listed in the available information; follow Fortinet advisories and apply vendor fixes when they are published.

Does CVE-2026-26084 require authentication?

No; the vulnerability allows unauthenticated access via crafted HTTP requests to FortiSandbox HTTP interfaces.

References