Skip to content
FG-IR-26-100

FG-IR-26-100

fortiguard.fortinet.com • July 23, 2026

An Improper Neutralization of Special Elements used in an OS Command ('OS command injection') vulnerability [CWE-78] in FortiSandbox may allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.

FortiSanbox PaaS 5.0 is not impacted by the issue and hence customers do not need to perform any action.

2026-04-14: Initial publication

Extracted Entities

Platforms (1)

Vulnerabilities (1)