V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2026-25089
CVE
CriticalConfirmedExploit available

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 t…

CVSS
9.8
Critical
EPSS
0.03
p83
Published
2026-01-01
Updated
2026-01-01
Description

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests

Tags · CWE
Pre-auth
CWE-78
CAPEC-6
CAPEC-15
CAPEC-43
CAPEC-88
CAPEC-108
Affected products
Fortisandbox 4.2.0–4.2.8Fortisandbox 4.4.0–4.4.9Fortisandbox 5.0.0–5.0.6Fortisandbox_cloud 5.0.4–5.0.6Fortisandbox_paas 5.0.4–5.0.6
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2026-01-01
Published
2026-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.027 · p83
Known exploited (KEV)
No
Known exploits — Сканер-ВС
CVE-2026-25089
github-poc · https://github.com/0xBlackash/CVE-2026-25089
Enterprise
Affected products
ProductVendorStatus
fortisandbox*Tracked
fortisandbox_cloud*Tracked
fortisandbox_paas*Tracked