CVE-2026-26083

fortisandbox: Missing Authorization (CVE-2026-26083)

criticalEPSS 0.7 %

Beschreibung

Ein Autorisierungsfehler in Fortinet FortiSandbox 5.0.0 bis 5.0.1, FortiSandbox 4.4.0 bis 4.4.8, FortiSandbox Cloud 5.0.2 bis 5.0.5, allen Versionen von FortiSandbox PaaS 23.4, allen Versionen von FortiSandbox PaaS 23.3, allen Versionen von FortiSandbox PaaS 23.1, allen Versionen von FortiSandbox PaaS 22.2, allen Versionen von FortiSandbox PaaS 22.1, allen Versionen von FortiSandbox PaaS 21.4, allen Versionen von FortiSandbox PaaS 21.3 und FortiSandbox PaaS 5.0.0 bis 5.0.1 sowie 4.4.5 bis 4.4.8 könnte es einem nicht authentifizierten Angreifer ermöglichen, über HTTP-Anfragen unautorisierten Code oder Befehle auszuführen.

Metriken

Severity
critical
kein öffentlicher PoC bekannt
9.8
Quelle: nvd-v3
52.3 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
0.7 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-05-12 16:54 UTC
CWE-862

Weakness-Klassen (CWE)

  • CWE-862Class

    Missing Authorization

    The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

    cwe.mitre.org →

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • fortinet

    fortisandbox4.4.0 – 4.4.9

  • fortinet

    fortisandbox5.0.0 – 5.0.2

  • fortinet

    fortisandbox_cloud23.1.4245 – 23.4.4374

  • fortinet

    fortisandbox_cloud5.0.2 – 5.0.6

  • fortinet

    fortisandbox_cloud

  • fortinet

    fortisandbox_paas21.3.4055 – 23.4.4374

  • fortinet

    fortisandbox_paas4.4.5 – 4.4.9

  • fortinet

    fortisandbox_paas5.0.0 – 5.0.2

Quellen & Referenzen

IDCVE-2026-26083