{"id":"CVE-2026-39808","title":"A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector…","summary":"A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-78"],"vendor":"fortinet","product":"fortisandbox","affected":["fortisandbox >= 4.4.0, <= 4.4.9"],"published":"2026-04-14","updated":"2026-07-16","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-39808","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-100","label":"psirt@fortinet.com"},{"url":"https://github.com/samu-delucas/CVE-2026-39808","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-39808","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","exploit-available"],"epss":0.92819,"epssPercentile":0.99825,"kev":true,"kevDateAdded":"2026-07-16","kevDueDate":"2026-07-19","kevRansomware":false,"exploited":true,"ingestedAt":"2026-07-16T18:56:41.173Z","exploits":{"github":5,"githubRepos":["https://github.com/samu-delucas/CVE-2026-39808","https://github.com/0xBlackash/CVE-2026-39808","https://github.com/ynsmroztas/FortiSandbox-RCE-Exploit-CVE-2026-39808"],"nuclei":["CVE-2026-39808"],"checkedAt":"2026-09-23T07:14:02.737Z"},"exploitAvailable":true,"slug":"CVE-2026-39808","body":"## Overview\n\nA improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>\n\n## Affected\n\n- `fortisandbox >= 4.4.0, <= 4.4.9`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"hadal","depthScore":97,"depthScoreParts":{"impact":53.9,"likelihood":18.6,"exploitation":25,"ransomware":0},"changes":[{"seq":5144,"id":"CVE-2026-39808","ts":1788887250883,"field":"exploit_available","old":"false","new":"true"},{"seq":4027,"id":"CVE-2026-39808","ts":1788886366789,"field":"exploit_available","old":"true","new":"false"},{"seq":2838,"id":"CVE-2026-39808","ts":1788883033488,"field":"exploit_available","old":"false","new":"true"},{"seq":1867,"id":"CVE-2026-39808","ts":1788882436336,"field":"exploit_available","old":"true","new":"false"},{"seq":965,"id":"CVE-2026-39808","ts":1788881870650,"field":"exploit_available","old":"false","new":"true"},{"seq":88,"id":"CVE-2026-39808","ts":1784920475551,"field":"epss","old":"0.84158","new":"0.89691"},{"seq":67,"id":"CVE-2026-39808","ts":1784314989016,"field":"epss","old":"0.48668","new":"0.84158"}]}