← All Advisories

Fortinet FortiSandbox 4.4.x and 5.0.x Improper Access Control Lets Attackers Access Sensitive Information via Crafted HTTP Requests

Last refreshed2026-09-28

Status: NEW  |  Advisory ID: CVE-2026-26084

Key Details

CVECVE-2026-26084
CVSS Score / Version9.9 (Critical) / CVSS v3.1
Updated2026-09-08
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is changed; confidentiality impact is low; integrity impact is low; availability impact is high.
Classified asCWE-284 (Improper Access Control)

What to Know

A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-26084
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-26084