CVE-2026-25836
Eine unsachgemäße Neutralisierung spezieller Elemente in einem os-Befehl ('os-Befehleinschleusung')-Sicherheitsproblem in Fortinet FortiS… (CVE-2026-25836)
mediumEPSS 1.8 %
Beschreibung
Eine unsachgemäße Neutralisierung spezieller Elemente in einem os-Befehl ('os-Befehleinschleusung')-Sicherheitsproblem in Fortinet FortiSandbox Cloud 5.0.4, FortiSandbox PaaS 5.0.4 könnte es einem privilegierten Angreifer mit Super-Admin-Profil und CLI-Zugriff ermöglichen, über gefälschte HTTP-Anfragen nicht autorisierte Code oder Befehle auszuführen.
Metriken
Severity
medium
98.54
kein öffentlicher PoC bekannt
6.7
Veröffentlicht
2026-03-10 16:44 UTC
CWE-78
Weakness-Klassen (CWE)
CWE-78Base
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
cwe.mitre.org →
Quellen & Referenzen
IDCVE-2026-25836