CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-25089

KEV Critical · CVSS 9.8

Fortinet FortiSandbox — Unauthenticated OS Command Injection (CWE-78)

CVSS
9.8
nvd
EPSS
KEV
Listed
2026-07-16
Class
other
CWE-78

Description

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests

Search profile — drives PoC discovery

Symbols HTTP request handlercommand injectionos command executionunauthenticated endpointFG-IR-26-141
Keywords CVE-2026-25089FortiSandboxOS command injectionunauthenticated RCEFG-IR-26-141FortiSandbox CloudFortiSandbox PaaSHTTP request command injectionFortinet RCE
Versions: FortiSandbox 5.0.0–5.0.5, 4.4.0–4.4.8, 4.2 all versions; FortiSandbox Cloud 5.0.4–5.0.5; FortiSandbox PaaS 5.0.4–5.0.5

Ranked PoCs (2) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-06-12T00:00:30.000Z · profiled 2026-06-16T18:19:23.017Z