ID

VAR-202605-3727


CVE

CVE-2026-26083


TITLE

fortinet's FortiSandbox Vulnerabilities related to lack of authentication in multiple products, such as

Trust: 0.8

sources: JVNDB: JVNDB-2026-015776

DESCRIPTION

A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 through 5.0.5, FortiSandbox PaaS 23.4 all versions, FortiSandbox PaaS 23.3 all versions, FortiSandbox PaaS 23.1 all versions, FortiSandbox PaaS 22.2 all versions, FortiSandbox PaaS 22.1 all versions, FortiSandbox PaaS 21.4 all versions, FortiSandbox PaaS 21.3 all versions, FortiSandbox PaaS 5.0.0 through 5.0.1, FortiSandbox PaaS 4.4.5 through 4.4.8 may allow an unauthenticated attacker to execute unauthorized code or commands via HTTP requests. All information handled by the software may be rewritten. Furthermore, the software may stop working completely. Furthermore, attacks that exploit this vulnerability will not affect other software

Trust: 1.62

sources: NVD: CVE-2026-26083 // JVNDB: JVNDB-2026-015776

AFFECTED PRODUCTS

vendor:fortinetmodel:fortisandbox cloudscope:gteversion:5.0.2

Trust: 1.0

vendor:fortinetmodel:fortisandbox paasscope:gteversion:5.0.0

Trust: 1.0

vendor:fortinetmodel:fortisandbox paasscope:ltversion:4.4.9

Trust: 1.0

vendor:fortinetmodel:fortisandboxscope:ltversion:4.4.9

Trust: 1.0

vendor:fortinetmodel:fortisandbox cloudscope:gteversion:23.1.4245

Trust: 1.0

vendor:fortinetmodel:fortisandboxscope:gteversion:5.0.0

Trust: 1.0

vendor:fortinetmodel:fortisandbox paasscope:lteversion:23.4.4374

Trust: 1.0

vendor:fortinetmodel:fortisandboxscope:gteversion:4.4.0

Trust: 1.0

vendor:fortinetmodel:fortisandbox cloudscope:lteversion:23.4.4374

Trust: 1.0

vendor:fortinetmodel:fortisandbox paasscope:gteversion:21.3.4055

Trust: 1.0

vendor:fortinetmodel:fortisandbox cloudscope:eqversion:24.1.4436

Trust: 1.0

vendor:fortinetmodel:fortisandbox paasscope:gteversion:4.4.5

Trust: 1.0

vendor:fortinetmodel:fortisandbox paasscope:ltversion:5.0.2

Trust: 1.0

vendor:fortinetmodel:fortisandboxscope:ltversion:5.0.2

Trust: 1.0

vendor:fortinetmodel:fortisandbox cloudscope:ltversion:5.0.6

Trust: 1.0

vendor:フォーティネットmodel:fortisandbox cloudscope: - version: -

Trust: 0.8

vendor:フォーティネットmodel:fortisandbox paasscope: - version: -

Trust: 0.8

vendor:フォーティネットmodel:fortisandboxscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2026-015776 // NVD: CVE-2026-26083

CVSS

SEVERITY

CVSSV2

CVSSV3

psirt@fortinet.com: CVE-2026-26083
value: CRITICAL

Trust: 1.0

OTHER: JVNDB-2026-015776
value: CRITICAL

Trust: 0.8

psirt@fortinet.com: CVE-2026-26083
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.1

Trust: 1.0

OTHER: JVNDB-2026-015776
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2026-015776 // NVD: CVE-2026-26083

PROBLEMTYPE DATA

problemtype:CWE-862

Trust: 1.0

problemtype:Lack of authentication (CWE-862) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2026-015776 // NVD: CVE-2026-26083

PATCH

title:PSIRT | FortiGuard Labsurl:https://fortiguard.fortinet.com/psirt/FG-IR-26-136

Trust: 0.8

sources: JVNDB: JVNDB-2026-015776

EXTERNAL IDS

db:NVDid:CVE-2026-26083

Trust: 2.6

db:JVNDBid:JVNDB-2026-015776

Trust: 0.8

sources: JVNDB: JVNDB-2026-015776 // NVD: CVE-2026-26083

REFERENCES

url:https://fortiguard.fortinet.com/psirt/fg-ir-26-136

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2026-26083

Trust: 0.8

sources: JVNDB: JVNDB-2026-015776 // NVD: CVE-2026-26083

SOURCES

db:JVNDBid:JVNDB-2026-015776
db:NVDid:CVE-2026-26083

LAST UPDATE DATE

2026-06-19T23:31:40.982000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2026-015776date:2026-05-18T02:23:00
db:NVDid:CVE-2026-26083date:2026-05-15T13:42:07.463

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2026-015776date:2026-05-18T00:00:00
db:NVDid:CVE-2026-26083date:2026-05-12T18:16:39.817