CVE-2026-39808
Fortinet FortiSandbox OS Command Injection Vulnerability
Description
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>
Description as published by the source, in English.
Key facts
- Published
- 2026-04-14
- Last modified
- 2026-07-17
- Assigned by
- psirt@fortinet.com
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Scored by
- psirt@fortinet.com
- Probability of exploitation
-
89.7 %
among the highest of all known vulnerabilities
EPSS, next 30 days, model v2026.06.15 - Fix available
- Not registered in the sources
Actively exploited
CISA added this vulnerability to the Known Exploited Vulnerabilities catalogue on 2026-07-16, with a remediation deadline of 2026-07-19 for US federal agencies.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Affected products
| Vendor | Product | Versions | Status |
|---|---|---|---|
| Fortinet | Fortisandbox | ≥ 4.4.0, ≤ 4.4.9 | Affected |
Weakness type
-
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS …
References
- https://fortiguard.fortinet.com/psirt/FG-IR-26-100
- https://github.com/samu-delucas/CVE-2026-39808
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-39808
Related at Berigo
Articles
-
Approved partners get access to a model that finds unknown vulnerabilities
Same product
2026-08-12
OpenAI is expanding Daybreak with two access levels and releasing GPT-5.6-Cyber, a model trained for tasks such as finding zero-day vulnerabilities a…
-
Official installers for QuickFox VPN carried a backdoor for nearly a year
Same product
2026-08-07
Fortinet has found that the QuickFox VPN installers spread a backdoor for nearly a year. The backdoor was only installed on machines that looked like…
-
FortiBleed: over 30,000 valid Fortinet credentials found in attacker hands
Same product
2026-06-18
SOCRadar has found 30,791 verified working credentials for Fortinet firewalls and VPN gateways across 194 countries.
-
Critical FortiClient EMS flaw exploited before the advisory landed
Same product
2026-04-04
CVE-2026-35616 enables unauthenticated code execution in FortiClient EMS 7.4.5 and 7.4.6. Fortinet has issued a hotfix to install now.
Does this affect you?
A vulnerability matters only if you run the product, in an affected version, somewhere an attacker can reach.