CVE-2026-84387

Fortinet FortiSandbox: Mehrere Schwachstellen

Beschreibung

Eine unsachgemäße Neutralisierung spezieller Elemente in einem Befehl ('Befehlseinschleusung')-Sicherheitsanfälligkeit in Fortinet FortiSandbox 5.2.0, FortiSandbox 5.0.0 bis 5.0.6 und FortiSandbox 4.4.0 bis 4.4.9 könnte es einem Angreifer ermöglichen, über <Angriffsweg einfügen> nicht autorisierten Code oder Befehle auszuführen.

Metriken

Severity
high
kein öffentlicher PoC bekannt
7.2
Quelle: cna-v3
56.9 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
0.9 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-09-10 11:38 UTC
CWE-77

Weakness-Klassen (CWE)

  • CWE-77Class

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

    The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-09-08 18:21 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-84387","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  2. New CVE Received2026-09-08 17:18 UTC· psirt@fortinet.com
    • Description: A improper neutralization of special elements used in a command ('command injection') vulnerability in Fortinet FortiSandbox 5.2.0, FortiSandbox 5.0.0 through 5.0.6, FortiSandbox 4.4.0 through 4.4.9 may allow attacker to execute unauthorized code or commands via <insert attack vector here>
    • CVSS V3.1: AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
    • CWE: CWE-77
    • Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/84xxx/CVE-2026-84387.json">CVE-2026-84387</a>

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • Fortinet

    FortiSandbox< 4.4.10

    gefixt in 4.4.10

  • Fortinet

    FortiSandbox< 4.4.9

    gefixt in 4.4.9

  • Fortinet

    FortiSandbox< 5.0.6

    gefixt in 5.0.6

  • Fortinet

    FortiSandbox< 5.0.7

    gefixt in 5.0.7

  • Fortinet

    FortiSandbox< 5.2.1

    gefixt in 5.2.1

  • Fortinet

    FortiSandboxCloud <5.0.6

  • Fortinet

    FortiSandboxPaaS <5.0.6

Verknüpfte CVEs

IDCVE-2026-84387