Vulnerability Intelligence Report
CVE-2026-25836
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox Cloud 5.0.4, FortiSandbox PaaS 5.0.4 may allow a privileged attacker with super-admin profile and CLI access to execute unauthorized code or commands via crafted HTTP requests.
No Active Exploit Signals
CVSS Base Score
6.7
MEDIUM
Exploitability:1.3
Impact Score:5.9
EPSS Probability:1.76%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-78 ↗Execute unauthorized code or commands
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Fortinet | FortiSandbox Cloud | 5.0.4 (affected) |
| Fortinet | FortiSandbox PaaS | 5.0.4 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
1.760%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Fortinet, Inc. · Vendor · USA |
| Reserved | 2026-02-06T08:48:58 |
| Published | 2026-03-10T16:44:06 |
| Last Updated | 2026-05-12T16:54:09 |
Community Chatter & Buzz