CVE-2026-27316 PUBLISHED

Assigner: fortinet
Reserved: 19.02.2026 Published: 14.04.2026 Updated: 14.04.2026

A insufficiently protected credentials vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4 all versions, FortiSandbox PaaS 5.0.1 through 5.0.5 may allow an authenticathed administrator to read LDAP server credentials via client-side inspection.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C
CVSS Score: 2.5

Product Status

Vendor Fortinet
Product FortiSandbox
Versions Default: unaffected
  • affected from 5.0.0 to 5.0.5 (incl.)
  • affected from 4.4.0 to 4.4.9 (incl.)
Vendor Fortinet
Product FortiSandbox PaaS
Versions Default: unaffected
  • Version 23.4.4374 is affected
  • Version 23.4.4350 is affected
  • Version 23.3.4329 is affected
  • Version 23.1.4245 is affected
  • Version 22.2.4151 is affected
  • Version 22.2.4134 is affected
  • Version 22.1.4113 is affected
  • Version 21.4.4072 is affected
  • Version 21.3.4055 is affected
  • affected from 5.0.1 to 5.0.5 (incl.)

Solutions

Upgrade to upcoming FortiSandbox version 5.2.0 or above Upgrade to FortiSandbox version 5.0.6 or above Upgrade to FortiSandbox PaaS version 5.0.6 or above

References

Problem Types

  • Information disclosure CWE