Project Subscriptions
No advisories yet.
Solution
Fortinet remediated this issue in FortiSandbox Cloud version 5.0.5 and hence customers do not need to perform any action.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-26-096 |
|
Wed, 18 Mar 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fortinet fortisandbox Cloud
|
|
| CPEs | cpe:2.3:a:fortinet:fortisandbox_cloud:5.0.4:*:*:*:*:*:*:* | |
| Vendors & Products |
Fortinet fortisandbox Cloud
|
Tue, 10 Mar 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Mar 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox Cloud 5.0.4 may allow a privileged attacker with super-admin profile and CLI access to execute unauthorized code or commands via crafted HTTP requests. | |
| First Time appeared |
Fortinet
Fortinet fortisandboxcloud |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:fortinet:fortisandboxcloud:5.0.4:*:*:*:*:*:*:* | |
| Vendors & Products |
Fortinet
Fortinet fortisandboxcloud |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2026-03-11T03:56:56.585Z
Reserved: 2026-02-06T08:48:58.542Z
Link: CVE-2026-25836
Updated: 2026-03-10T20:30:12.938Z
Status : Analyzed
Published: 2026-03-10T18:18:38.090
Modified: 2026-03-18T13:04:12.167
Link: CVE-2026-25836
No data.
OpenCVE Enrichment
Updated: 2026-03-11T11:49:37Z