Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026091401090505 | Publication Time | 2026-09-14 13:39:06 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026-09-14 13:39:06 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS Contain a Critical Cybersecurity Vulnerability (CVE-2026-26084) |
|||
| [Content]
Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202609-00000012 The web interfaces of Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain a Missing Access Control vulnerability (CVE-2026-26084, CVSS: 9.9), which allows an unauthenticated attacker to access sensitive information through specially crafted HTTP requests. Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed) |
|||
| [Affected Platform]
FortiSandbox versions 5.0.0 to 5.0.5 |
|||
|
[Recommended Actions] Please update to the following versions: FortiSandbox version 5.0.6 or later |
|||
|
[Reference] |
|||