ID

VAR-202607-3327


CVE

CVE-2026-59835


TITLE

fortinet's FortiSandbox Vulnerability in leaking resources to the wrong area in

Trust: 0.8

sources: JVNDB: JVNDB-2026-023914

DESCRIPTION

A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests. Fortinet FortiSandbox 5.0.0 from 5.0.2 , and FortiSandbox 4.4.3 from 4.4.8 In this system, a vulnerability exists where resources are exposed to a false sphere. VNC It may be possible to access the server.- All information handled by the software may be leaked to external parties. - Some of the information handled by the software may be overwritten. - Part of the software may stop working

Trust: 1.62

sources: NVD: CVE-2026-59835 // JVNDB: JVNDB-2026-023914

AFFECTED PRODUCTS

vendor:fortinetmodel:fortisandboxscope:ltversion:4.4.9

Trust: 1.0

vendor:fortinetmodel:fortisandboxscope:gteversion:4.4.3

Trust: 1.0

vendor:fortinetmodel:fortisandboxscope:ltversion:5.0.3

Trust: 1.0

vendor:fortinetmodel:fortisandboxscope:gteversion:5.0.0

Trust: 1.0

vendor:フォーティネットmodel:fortisandboxscope: - version: -

Trust: 0.8

vendor:フォーティネットmodel:fortisandboxscope:eqversion: -

Trust: 0.8

vendor:フォーティネットmodel:fortisandboxscope:eqversion:4.4.3 that's all 4.4.9

Trust: 0.8

vendor:フォーティネットmodel:fortisandboxscope:eqversion:5.0.0 that's all 5.0.3

Trust: 0.8

sources: JVNDB: JVNDB-2026-023914 // NVD: CVE-2026-59835

CVSS

SEVERITY

CVSSV2

CVSSV3

psirt@fortinet.com: CVE-2026-59835
value: HIGH

Trust: 1.0

OTHER: JVNDB-2026-023914
value: HIGH

Trust: 0.8

psirt@fortinet.com: CVE-2026-59835
baseSeverity: HIGH
baseScore: 8.6
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: LOW
availabilityImpact: LOW
exploitabilityScore: 3.9
impactScore: 4.7
version: 3.1

Trust: 1.0

OTHER: JVNDB-2026-023914
baseSeverity: HIGH
baseScore: 8.6
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: LOW
availabilityImpact: LOW
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2026-023914 // NVD: CVE-2026-59835

PROBLEMTYPE DATA

problemtype:CWE-668

Trust: 1.0

problemtype:Leakage of resources to the wrong area (CWE-668) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2026-023914 // NVD: CVE-2026-59835

PATCH

title:PSIRT | FortiGuard Labsurl:https://fortiguard.fortinet.com/psirt/FG-IR-26-145

Trust: 0.8

sources: JVNDB: JVNDB-2026-023914

EXTERNAL IDS

db:NVDid:CVE-2026-59835

Trust: 2.6

db:JVNDBid:JVNDB-2026-023914

Trust: 0.8

sources: JVNDB: JVNDB-2026-023914 // NVD: CVE-2026-59835

REFERENCES

url:https://fortiguard.fortinet.com/psirt/fg-ir-26-145

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2026-59835

Trust: 0.8

sources: JVNDB: JVNDB-2026-023914 // NVD: CVE-2026-59835

SOURCES

db:JVNDBid:JVNDB-2026-023914
db:NVDid:CVE-2026-59835

LAST UPDATE DATE

2026-07-24T19:49:36.335000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2026-023914date:2026-07-17T02:09:00
db:NVDid:CVE-2026-59835date:2026-07-15T15:00:41.437

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2026-023914date:2026-07-17T00:00:00
db:NVDid:CVE-2026-59835date:2026-07-14T16:17:02.593