CVE-2026-26084
CRITICAL9.9CVSS v3
—CVSS v2
0.24%
EPSS (exploit probability)
CWE-284CWE
Description
A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests.
CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H
Affected routers (0)
No routers currently mapped to this CVE in our database.