A critical authorization vulnerability (CVE-2026-26084) in Fortinet FortiSandbox allows unauthenticated attackers to access sensitive information via specially crafted HTTP requests without user interaction. The vulnerability has a CVSS 3.1 score of 9.9 (CRITICAL). Fortinet has released patches for this and other vulnerabilities across multiple products including FortiAnalyzer, FortiOS, FortiPAM, FortiProxy, FortiSandbox, FortiManager, FortiClient Windows, FortiSIEM, and FortiSOAR.
Fortinet heeft kwetsbaarheden verholpen in FortiAnalyzer, FortiOS, FortiPAM, FortiProxy, FortiSandbox, FortiManager, FortiManager Cloud, FortiMonitorOnSight, FortiClient Windows, FortiSIEM en FortiSOAR. De kwetsbaarheden betreffen verschillende typen fouten in meerdere Fortinet-producten. De ernstigste kwetsbaarheid met kenmerk CVE-2026-26084 heeft een CVSS-score van 8,9. Het betreft een autorisatiekwetsbaarheid in Fortinet FortiSandbox waardoor een ongeauthenticeerde kwaadwillende via speciaal vervaardigde HTTP-verzoeken toegang kan krijgen tot gevoelige informatie. De kwetsbaarheid vereist geen gebruikersinteractie en kan via het netwerk worden misbruikt.