Mastodon Mastodon Mastodon Mastodon

Fortinet discloses FortiSandbox vulnerability — unauthenticated access to sensitive data

Photo of author

CyberSecureFox Editorial Team

Published:

Fortinet has published security advisory FG-IR-26-166 describing an Improper Access Control vulnerability (CWE-284) in the web interface of FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS. According to the vendor advisory, the vulnerability has been assigned a CVSSv3 score of 8.9 (high severity) and allows an unauthenticated attacker to gain access to sensitive information via specially crafted HTTP requests. Organizations using the affected products should immediately check whether the FortiSandbox web interface is accessible from untrusted networks and refer to the full text of the Fortinet advisory for details on affected versions and updates.

Technical details of the vulnerability

The Fortinet advisory classifies the issue as an Improper Access Control vulnerability (CWE-284). The affected products are:

  • FortiSandbox (on-premise)
  • FortiSandbox Cloud
  • FortiSandbox PaaS

The vulnerable component is the management web interface (WEB UI) of the listed products. The attack vector is sending specially crafted HTTP requests, with no authentication required for exploitation. The result is access to sensitive information.

It is worth noting the discrepancy between the advisory title and its content. The title — “Unauthenticated Control of NAT Rules Leading to Exposure of Sensitive Information” — mentions unauthenticated control of NAT rules, while the body of the advisory describes only improper access control and data leakage without detailing the mechanism for manipulating NAT rules. Thus, the confirmed impact is access to sensitive information; the specific mechanics of NAT rule manipulation are not disclosed in the publicly available text of the advisory.

At the time of publication, the available fragment of the advisory does not specify a CVE identifier, ranges of affected versions, fixed versions, or the upgrade path. There is also no evidence of active exploitation of the vulnerability.

Impact assessment

FortiSandbox is a solution for dynamic malware analysis widely used in corporate environments to protect against targeted attacks. Compromise of its web interface entails a number of serious risks:

  • Disclosure of data on analyzed samples — an attacker may obtain information about malicious files the organization is investigating, revealing details about ongoing incidents and the defenders’ level of awareness.
  • Leakage of configuration data — access to sandbox settings may reveal the network architecture and integrations with other security tools.
  • Broad coverage — the vulnerability affects all three deployment options (on-premise, cloud, and PaaS), expanding the attack surface.

The CVSSv3 score of 8.9 indicates high severity. The lack of an authentication requirement makes the vulnerability particularly dangerous for deployments where the FortiSandbox web interface is accessible from untrusted networks or from the internet.

We have previously written about critical vulnerabilities in FortiSandbox — the new advisory continues the trend of serious security issues being identified in this product line.

Recommendations

Since the available fragment of the advisory does not contain information about affected and fixed versions, it is recommended to:

  1. Refer to the full text of the advisory on the Fortinet PSIRT page to obtain up-to-date information on affected versions and available updates.
  2. Restrict network access to the FortiSandbox web interface — ensure that the WEB UI is not accessible from the internet or from untrusted network segments. Given that the vulnerability is exploited without authentication via HTTP requests, network isolation of the management interface is the top priority.
  3. Review access logs for the FortiSandbox web interface for anomalous HTTP requests from unauthorized sources.
  4. Monitor updates on the Fortinet PSIRT portal — the advisory is dated 8 September 2026 and may be supplemented with information on patches and affected versions.

Organizations operating FortiSandbox in any of the three deployment models should prioritize checking the accessibility of the web interface from untrusted networks and implement network segmentation until a patch is released. Given the CVSSv3 score of 8.9 and the absence of an authentication requirement, delaying the isolation of the management interface creates a real risk of sensitive data leakage.


CyberSecureFox Editorial Team

The CyberSecureFox Editorial Team covers cybersecurity news, vulnerabilities, malware campaigns, ransomware activity, AI security, cloud security, and vendor security advisories. Articles are prepared using official advisories, CVE/NVD data, CISA alerts, vendor publications, and public research reports. Content is reviewed before publication and updated when new information becomes available.

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.