---
id: CVE-2026-26084
title: >-
  A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through
  5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through
  5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access
  sensitive …
summary: >-
  A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through
  5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through
  5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access
  sensitive …
severity: critical
cvss: 9.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H'
cwe:
  - CWE-284
vendor: Fortinet
product: FortiSandbox PaaS
affected:
  - fortisandbox_paas >= 5.0.4 <= 5.0.5
  - FortiSandbox >= 5.0.0 <= 5.0.5
  - FortiSandbox >= 4.4.0 <= 4.4.8
  - FortiSandbox >= 4.2.1 <= 4.2.8
  - fortisandbox_cloud >= 5.0.4 <= 5.0.5
published: '2026-09-08'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T18:35:10.323'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-26084'
references:
  - url: 'https://fortiguard.fortinet.com/psirt/FG-IR-26-166'
    label: psirt@fortinet.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-08T17:31:09.979157Z'
scores:
  nvd: 9.9
  cna: 8.9
ingestedAt: '2026-09-08T17:06:31.889Z'
epss: 0.0039
epssPercentile: 0.30247
---

## Overview

A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
