CVE-2026-39813 is a path traversal vulnerability affecting Fortinet FortiSandbox versions 5.0.0 through 5.0.5 and 4.4.0 through 4.4.8. The flaw allows attackers to escalate privileges through manipulation of directory traversal sequences. This vulnerability impacts a widely deployed sandbox security solution, potentially affecting organizations relying on FortiSandbox for malware analysis and threat detection. The vulnerability carries a critical CVSS score of 9.8, indicating severe risk. It requires no authentication, no user interaction, and presents low attack complexity, making it accessible to remote attackers over the network. Successful exploitation could result in complete compromise of confidentiality, integrity, and availability of affected systems. There is currently no evidence of active exploitation in the wild, and the vulnerability does not appear on the Known Exploited Vulnerabilities catalog. While the EPSS score of 0.0008 suggests low probability of exploitation relative to other CVEs, organizations running affected FortiSandbox versions should prioritize patching given the critical severity rating and ease of exploitation. Community attention remains limited at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.4.0, < 4.4.9CPE matchmatch criteria | cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:* | ||
>= 5.0.0, < 5.0.6CPE matchmatch criteria | cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.