SB2026090973 - Improper access control in FortiSandbox



SB2026090973 - Improper access control in FortiSandbox

Published: September 9, 2026

Security Bulletin ID SB2026090973
CSH Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper access control (CVE-ID: CVE-2026-26084)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

The vulnerability exists due to improper access control of Sensitive Information. An unauthenticated attacker can access sensitive information via crafted HTTP requests.


Remediation

Install update from vendor's website.