First published · Last updated
CVE-2026-39808: Fortinet FortiSandbox OS Command Injection Vulnerability
The source reports an OS command injection vulnerability in Fortinet FortiSandbox that could allow an unauthenticated attacker to execute unauthorized code or commands through crafted HTTP requests. It calls for applying mitigations in line with vendor instructions and applicable CISA guidance.
Categories: technology
Generated scores
Scores are based on the cited reporting and use a 1–10 scale. Read the methodology.
- Confidence
- 5/10
- Geographic reach
- 1/10
- Global importance
- 2/10
- Impact magnitude
- 3/10
- Positivity
- 2/10
- Urgency
- 5/10
Why it matters
The source identifies a potential route to unauthorized code execution and calls for mitigation or discontinuing use if mitigations are unavailable.

