Vulnerability Details CVE-2026-39808
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>
Exploit prediction scoring system (EPSS) score
EPSS Score 0.897
EPSS Ranking 99.8%
CVSS Severity
CVSS v3 Score 9.8
Proposed Action
Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
Ransomware Campaign
Unknown
Products affected by CVE-2026-39808
-
cpe:2.3:a:fortinet:fortisandbox:4.4.0
-
cpe:2.3:a:fortinet:fortisandbox:4.4.1
-
cpe:2.3:a:fortinet:fortisandbox:4.4.2
-
cpe:2.3:a:fortinet:fortisandbox:4.4.3
-
cpe:2.3:a:fortinet:fortisandbox:4.4.4
-
cpe:2.3:a:fortinet:fortisandbox:4.4.5
-
cpe:2.3:a:fortinet:fortisandbox:4.4.6
-
cpe:2.3:a:fortinet:fortisandbox:4.4.7
-
cpe:2.3:a:fortinet:fortisandbox:4.4.8
-
cpe:2.3:a:fortinet:fortisandbox:4.4.9