CVE-2026-39808

Analyzed
Published: 14 Apr 2026, 15:38
Last modified:17 Jul 2026, 03:56

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.1 (nvd)
EPSS Score
91.21% CRITICAL
91% probability +42.54%
KEV
Listed
CISA
1 listing
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

14 Apr 2026, 15:38
Published
Vulnerability first disclosed
16 Jul 2026, 00:00
Added to CISA KEV
Fortinet FortiSandbox OS Command Injection Vulnerability
17 Jul 2026, 03:56
Last Modified
Vulnerability information updated
19 Jul 2026, 00:00
CISA Remediation Due
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Description

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

CVSS Metrics

  • v3.1CRITICALScore: 9.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 91.21% Percentile: 100%

Techniques & Countermeasures

  • CWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

    The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Affected Systems

  • fortinetfortisandbox

    ≥ 4.4.0, ≤ 4.4.8 | ≥ 4.4.0, ≤ 4.4.9

  • fortinetfortisandbox_paas

    23.4.4374 | 23.4.4350 | 23.3.4329 | 23.1.4245 | 22.2.4151 | 22.2.4134 | 22.1.4113 | 21.4.4072 | 21.3.4055

References (3)