CVE-2026-39813 PUBLISHED

Assigner: fortinet
Reserved: 07.04.2026 Published: 14.04.2026 Updated: 14.04.2026

A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via <insert attack vector here>

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
CVSS Score: 9.1

Product Status

Vendor Fortinet
Product FortiSandbox
Versions Default: unaffected
  • affected from 5.0.0 to 5.0.5 (incl.)
  • affected from 4.4.0 to 4.4.8 (incl.)
Vendor Fortinet
Product FortiSandbox Cloud
Versions Default: unaffected
  • Version 24.1 is affected
  • Version 23.4 is affected
  • affected from 5.0.4 to 5.0.5 (incl.)

Solutions

Upgrade to upcoming FortiSandbox version 5.2.0 or above Upgrade to FortiSandbox version 5.0.6 or above Upgrade to FortiSandbox version 4.4.9 or above

References

Problem Types

  • Escalation of privilege CWE