OS Command Injection in FortiSandbox - CVE-2026-25089
Published: June 9, 2026
Vulnerability identifier: #VU134004
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2026-25089
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: Fortinet, Inc
Affected software:
FortiSandbox
FortiSandbox
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The vulnerability exists due to improper neutralization of special elements used in an os command ('os command injection') on start vnc feature. An unauthenticated attacker can execute unauthorized commands via specifically crafted HTTP requests.
How to mitigate CVE-2026-25089
Install update from vendor's website.