CVE-2026-26084

Fortinet FortiSandbox: Mehrere Schwachstellen

criticalEPSS 0.2 %

Beschreibung

Ein Zugriffskontrollfehler in Fortinet FortiSandbox 5.0.0 bis 5.0.5, FortiSandbox 4.4.0 bis 4.4.8, FortiSandbox Cloud 5.0.4 bis 5.0.5 und FortiSandbox PaaS 5.0.4 bis 5.0.5 kann es einem Angreifer ermöglichen, über manipulierte HTTP-Anfragen auf vertrauliche Informationen zuzugreifen.

Metriken

Severity
critical
kein öffentlicher PoC bekannt
9.9
Quelle: cna-v3
14.8 %
Erhöht — CVE ist relevanter als mindestens 10 % der heute bewerteten CVEs.
0.2 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-09-10 11:38 UTC
CWE-284

Weakness-Klassen (CWE)

  • CWE-284Pillar

    Improper Access Control

    The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-09-08 18:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-26084","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…
  2. New CVE Received2026-09-08 17:17 UTC· psirt@fortinet.com
    • Description: A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests.
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H
    • CWE: CWE-284
    • Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/26xxx/CVE-2026-26084.json">CVE-2026-26084</a>

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • Fortinet

    FortiSandbox< 4.4.10

    gefixt in 4.4.10

  • Fortinet

    FortiSandbox< 4.4.9

    gefixt in 4.4.9

  • Fortinet

    FortiSandbox< 5.0.6

    gefixt in 5.0.6

  • Fortinet

    FortiSandbox< 5.0.7

    gefixt in 5.0.7

  • Fortinet

    FortiSandbox< 5.2.1

    gefixt in 5.2.1

  • Fortinet

    FortiSandboxCloud <5.0.6

  • Fortinet

    FortiSandboxPaaS <5.0.6

Verknüpfte CVEs

Verknüpfte Empfehlungen

IDCVE-2026-26084