
CVE-2026-25089
CVE-2026-25089 is a critical OS Command Injection (CWE-78) vulnerability affecting multiple Fortinet FortiSandbox deployments.
An unauthenticated remote attacker can exploit this flaw by sending specially crafted HTTP requests, resulting in arbitrary command execution on the underlying operating system.
⚠️ Successful exploitation may lead to complete appliance compromise and remote code execution (RCE).
| Product | Vulnerable Versions |
|---|---|
| FortiSandbox | 5.0.0 – 5.0.5 |
| FortiSandbox | 4.4.0 – 4.4.8 |
| FortiSandbox | 4.2.x |
| Product | Patched Version |
|---|---|
| FortiSandbox | 5.0.6 |
| FortiSandbox | 4.4.9 |
| FortiSandbox Cloud | 5.0.6 |
| FortiSandbox PaaS | 5.0.6 |
CVSS v3.1 Score: 9.8 (Critical)
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attacker
│
▼
Crafted HTTP Request
│
▼
Vulnerable FortiSandbox Endpoint
│
▼
OS Command Injection
│
▼
Remote Code Execution
│
▼
System Compromise
Monitor for:
This repository is intended for:
The information provided must be used only in authorized and legal environments.
CVE-2026-25089
Made with ❤️ by Security Researchers
| Field | Value |
|---|
| CVE | CVE-2026-25089 |
| Severity | Critical |
| CWE | CWE-78 |
| Attack Type | OS Command Injection |
| Authentication | Not Required |
| User Interaction | None |
| Impact | Remote Code Execution |
| Exploitability | Remote |
| Vendor | Fortinet |
| FortiSandbox Cloud |
| 5.0.4 – 5.0.5 |
| FortiSandbox PaaS | 5.0.4 – 5.0.5 |
| Metric | Value |
|---|
| Attack Vector | Network |
| Attack Complexity | Low |
| Privileges Required | None |
| User Interaction | None |
| Confidentiality | High |
| Integrity | High |
| Availability | High |