ID

VAR-202604-3550


CVE

CVE-2026-39812


TITLE

fortinet's FortiSandbox Cross-site scripting vulnerabilities in multiple products, including

Trust: 0.8

sources: JVNDB: JVNDB-2026-012090

DESCRIPTION

A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox PaaS 5.0.0 through 5.0.5, FortiSandbox PaaS 4.4.0 through 4.4.8, FortiSandbox PaaS 4.2 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>. This vulnerability allows an attacker to... insert attack vector here It may be possible to execute malicious code or commands through this.Some of the information handled by the software may be leaked to the outside. Also, some of the information handled by the software may be rewritten. Furthermore, the software will not stop. Furthermore, attacks exploiting this vulnerability may affect other software

Trust: 1.62

sources: NVD: CVE-2026-39812 // JVNDB: JVNDB-2026-012090

AFFECTED PRODUCTS

vendor:fortinetmodel:fortisandbox cloudscope:lteversion:24.1.4436

Trust: 1.0

vendor:fortinetmodel:fortisandboxscope:gteversion:4.2.0

Trust: 1.0

vendor:fortinetmodel:fortisandbox cloudscope:lteversion:23.1.4260

Trust: 1.0

vendor:fortinetmodel:fortisandbox cloudscope:gteversion:23.3.4329

Trust: 1.0

vendor:fortinetmodel:fortisandboxscope:lteversion:4.2.8

Trust: 1.0

vendor:fortinetmodel:fortisandboxscope:gteversion:4.4.0

Trust: 1.0

vendor:fortinetmodel:fortisandbox cloudscope:eqversion:5.0.5

Trust: 1.0

vendor:fortinetmodel:fortisandbox cloudscope:gteversion:22.2.4134

Trust: 1.0

vendor:fortinetmodel:fortisandboxscope:ltversion:4.4.9

Trust: 1.0

vendor:fortinetmodel:fortisandbox cloudscope:eqversion:5.0.4

Trust: 1.0

vendor:fortinetmodel:fortisandboxscope:ltversion:5.0.6

Trust: 1.0

vendor:fortinetmodel:fortisandboxscope:gteversion:5.0.0

Trust: 1.0

vendor:フォーティネットmodel:fortisandboxscope: - version: -

Trust: 0.8

vendor:フォーティネットmodel:fortisandbox cloudscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2026-012090 // NVD: CVE-2026-39812

CVSS

SEVERITY

CVSSV2

CVSSV3

psirt@fortinet.com: CVE-2026-39812
value: MEDIUM

Trust: 1.0

OTHER: JVNDB-2026-012090
value: MEDIUM

Trust: 0.8

psirt@fortinet.com: CVE-2026-39812
baseSeverity: MEDIUM
baseScore: 4.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 1.7
impactScore: 2.7
version: 3.1

Trust: 1.0

OTHER: JVNDB-2026-012090
baseSeverity: MEDIUM
baseScore: 4.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2026-012090 // NVD: CVE-2026-39812

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.0

problemtype:Cross-site scripting (CWE-79) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2026-012090 // NVD: CVE-2026-39812

PATCH

title:PSIRT | FortiGuard Labsurl:https://fortiguard.fortinet.com/psirt/FG-IR-26-110

Trust: 0.8

sources: JVNDB: JVNDB-2026-012090

EXTERNAL IDS

db:NVDid:CVE-2026-39812

Trust: 2.6

db:JVNDBid:JVNDB-2026-012090

Trust: 0.8

sources: JVNDB: JVNDB-2026-012090 // NVD: CVE-2026-39812

REFERENCES

url:https://fortiguard.fortinet.com/psirt/fg-ir-26-110

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2026-39812

Trust: 0.8

sources: JVNDB: JVNDB-2026-012090 // NVD: CVE-2026-39812

SOURCES

db:JVNDBid:JVNDB-2026-012090
db:NVDid:CVE-2026-39812

LAST UPDATE DATE

2026-06-19T22:41:02.527000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2026-012090date:2026-04-23T01:11:00
db:NVDid:CVE-2026-39812date:2026-04-21T17:12:33.610

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2026-012090date:2026-04-23T00:00:00
db:NVDid:CVE-2026-39812date:2026-04-14T16:16:45.490