CVE-2026-26084
Fortinet FortiSandbox: Mehrere Schwachstellen
Beschreibung
Ein Zugriffskontrollfehler in Fortinet FortiSandbox 5.0.0 bis 5.0.5, FortiSandbox 4.4.0 bis 4.4.8, FortiSandbox Cloud 5.0.4 bis 5.0.5 und FortiSandbox PaaS 5.0.4 bis 5.0.5 kann es einem Angreifer ermöglichen, über manipulierte HTTP-Anfragen auf vertrauliche Informationen zuzugreifen.
Metriken
Weakness-Klassen (CWE)
CWE-284Pillar
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
cwe.mitre.org →
Re-Analyse & Statuswechsel
Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.
- CVE Modified2026-09-08 18:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-26084","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…
- New CVE Received2026-09-08 17:17 UTC· psirt@fortinet.com
- Description: A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests.
- CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H
- CWE: CWE-284
- Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/26xxx/CVE-2026-26084.json">CVE-2026-26084</a>
Betroffene Produkte
Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.
Fortinet
FortiSandbox< 4.4.10
gefixt in 4.4.10
Fortinet
FortiSandbox< 4.4.9
gefixt in 4.4.9
Fortinet
FortiSandbox< 5.0.6
gefixt in 5.0.6
Fortinet
FortiSandbox< 5.0.7
gefixt in 5.0.7
Fortinet
FortiSandbox< 5.2.1
gefixt in 5.2.1
Fortinet
FortiSandboxCloud <5.0.6
Fortinet
FortiSandboxPaaS <5.0.6