CVE-2026-39808 is an OS command injection vulnerability affecting Fortinet FortiSandbox versions 4.4.0 through 4.4.8 that could enable attackers to execute unauthorized code or commands on vulnerable systems. The vulnerability stems from improper neutralization of special elements in OS commands, representing a critical gap in input validation and sanitization controls. This flaw impacts the integrity and confidentiality of affected deployments, particularly those processing untrusted file submissions or external data. The vulnerability carries a CVSS 3.1 score of 9.8 CRITICAL with a network-based attack vector requiring no authentication, no user interaction, and low attack complexity. Successful exploitation would result in complete compromise of the affected system, allowing attackers to achieve high-impact objectives across confidentiality, integrity, and availability. The EPSS score of 0.11 indicates this vulnerability has lower exploitation probability compared to the CVE population baseline, though this should not diminish prioritization efforts. The vulnerability is not currently tracked on the Known Exploited Vulnerabilities catalog and shows no active exploitation in the wild. No public exploit code is readily available at this time, and community attention appears limited based on the inactive status on threat intelligence platforms. However, organizations running affected FortiSandbox versions should prioritize patching given the critical nature of the vulnerability and the potential for exploit development.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.4.0, <= 4.4.9CPE matchmatch criteria | cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.