---
id: CVE-2026-25089
title: >-
  A improper neutralization of special elements used in an os command ('os
  command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through
  5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions,
  FortiSandbox Cloud …
summary: >-
  A improper neutralization of special elements used in an os command ('os
  command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through
  5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions,
  FortiSandbox Cloud …
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: fortinet
product: fortisandbox
affected:
  - 'fortisandbox >= 4.2.0, <= 4.2.8'
  - 'fortisandbox >= 4.4.0, < 4.4.9'
  - 'fortisandbox >= 5.0.0, < 5.0.6'
  - 'fortisandbox_cloud >= 5.0.4, < 5.0.6'
  - 'fortisandbox_paas >= 5.0.4, < 5.0.6'
patched:
  - fortisandbox 5.0.6
  - fortisandbox_cloud 5.0.6
  - fortisandbox_paas 5.0.6
published: '2026-06-09'
updated: '2026-07-16'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-25089'
references:
  - url: 'https://fortiguard.fortinet.com/psirt/FG-IR-26-141'
    label: psirt@fortinet.com
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-25089
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.76112
epssPercentile: 0.99517
kev: true
kevDateAdded: '2026-07-16'
kevDueDate: '2026-07-19'
kevRansomware: false
exploited: true
ingestedAt: '2026-07-16T18:56:41.523Z'
exploits:
  github: 2
  githubRepos:
    - 'https://github.com/HORKimhab/CVE-2026-25089'
    - 'https://github.com/0xBlackash/CVE-2026-25089'
  checkedAt: '2026-09-25T08:20:53.428Z'
exploitAvailable: true
---

## Overview

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests

## Affected

- `fortisandbox >= 4.2.0, <= 4.2.8`
- `fortisandbox >= 4.4.0, < 4.4.9`
- `fortisandbox >= 5.0.0, < 5.0.6`
- `fortisandbox_cloud >= 5.0.4, < 5.0.6`
- `fortisandbox_paas >= 5.0.4, < 5.0.6`

## Remediation

Upgrade past the affected range:

- `fortisandbox 5.0.6`
- `fortisandbox_cloud 5.0.6`
- `fortisandbox_paas 5.0.6`
