CVE-2026-26084: FortiSandbox flaw leaks data without authentication
Fortinet disclosed CVE-2026-26084 (CWE-284, severity 8.9) in FortiSandbox: an unauthenticated attacker can send crafted HTTP requests via a specific NAT rule to read configuration and sample metadata. Affected versions are 4.4.0–4.4.8 and 5.0.0–5.0.5, fixed in 4.4.9 and 5.0.6. No exploitation in the wild has been observed.
- Severity 8.9, CWE-284, disclosed on 8 September 2026
- Affected: FortiSandbox 4.4.0–4.4.8 and 5.0.0–5.0.5, plus Cloud and PaaS 5.0.4–5.0.5
- Fixed in 4.4.9 and 5.0.6; 5.2 and Cloud 4.4 are not affected
- A specific NAT rule is the trigger, so exposure depends on network configuration
Read next
Security