CVE-2026-26083

CRITICAL

A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 through 5.0.5, FortiSandbox PaaS 23.4 all versions, Fo...

Affects 3 products across 1 vendor.

BCS6.28
CVSS 3.19.8
EPSS0.7%
Percentile51th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-862: Missing Authorization

Software does not check whether an authenticated actor has permission for the requested operation.

Related Attack Patterns (CAPEC)
CAPEC-665 Exploitation of Thunderbolt Protection Flaws
via CWE-862

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

{ "executive_summary": "A critical missing authorization vulnerability exists in multiple versions of Fortinet FortiSandbox and related products, allowing unauthorized access to sensitive functionalities and data.", "attack_vector_detail": "An attacker can exploit this vulnerability by sending specially crafted requests to the affected FortiSandbox instances, bypassing the intended authorization checks and gaining unauthorized access to the system.", "affected_components": [ "FortiSandbox 5.0.0 through 5.0.1", "FortiSandbox 4.4.0 through 4.4.8", "FortiSandbox Cloud 5.0.2 through 5.0.5", "FortiSandbox PaaS 23.4 all versions", "FortiSandbox PaaS 23.3 all versions", "FortiSandbox PaaS 23.1 all versions", "FortiSandbox PaaS 22.2 all versions", "FortiSandbox PaaS 22.1 all versions", "FortiSandbox PaaS 21.4 all versions", "FortiSandbox PaaS

BSID: BS-2026-GLOBAL-269824-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-26083?
{ "executive_summary": "A critical missing authorization vulnerability exists in multiple versions of Fortinet FortiSandbox and related products, allowing unauthorized access to sensitive functionalities and data.", "attack_vector_detail": "An attacker can exploit this vulnerability by sending specially crafted requests to the affected FortiSandbox instances, bypassing the intended authorization checks and gaining unauthorized access to the system.", "affected_components": [ "FortiSand
What is the CVSS score for CVE-2026-26083?
CVE-2026-26083 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 0.7%.
Is CVE-2026-26083 actively exploited?
No confirmed active exploitation of CVE-2026-26083 as of 2026-05-30.
How do I remediate CVE-2026-26083?
Priority: HIGH. Advisory: https://fortiguard.fortinet.com/psirt/FG-IR-26-136 PSIRT: [email protected]
What systems are affected by CVE-2026-26083?
CVE-2026-26083 affects: Fortinet, Fortinet, Fortinet.
Vulnerability Details
CVE IDCVE-2026-26083
BSIDBS-2026-GLOBAL-269824-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2026-05-12
Last Modified2026-05-15
ICS Relevance70%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 through 5.0.5, FortiSandbox PaaS 23.4 all versions, FortiSandbox PaaS 23.3 all versions, FortiSandbox PaaS 23.1 all versions, FortiSandbox PaaS 22.2 all versions, FortiSandbox PaaS 22.1 all versions, FortiSandbox PaaS 21.4 all versions, FortiSandbox PaaS 21.3 all versions, FortiSandbox PaaS 5.0.0 through 5.0.1, FortiSandbox PaaS 4.4.5 through 4.4.8 may allow an unauthenticated attacker to execute unauthorized code or commands via HTTP requests.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 through 5.0.5, FortiSandbox PaaS 23.4 all versions, FortiSandbox PaaS 23.3 all versions, FortiSandbox PaaS 23.1 all versions, FortiSandbox PaaS 22.2 all versions, FortiSandbox PaaS 22.1 all versions, FortiSandbox PaaS 21.4 all versions, FortiSandbox PaaS 21.3 all versions, FortiSandbox PaaS 5.0.0 through 5.0.1, FortiSandbox PaaS 4.4.5 through 4.4.8 may al CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Fortinet Fortisandbox
Fortinet Fortisandbox Cloud
Fortinet Fortisandbox Paas
Remediation
View Vendor Advisory →

Remediation Priority: HIGH

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 74 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash792f1d0fab1e2f963ed6a35021a5527f3dbfb1c7e02043a992fedded3618742ddc69809c81615a1bbb70f2ca02ce738054a365904d69132884cff9209be4c454
Related CVEs affecting Fortinet
CVE-2005-3057 10.0 The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and ot... CVE-2024-47575 9.8 A missing authentication for critical function in FortiManager 7.6.0, FortiMa... CVE-2024-23109 9.8 An improper neutralization of special elements used in an os command ('os com... CVE-2024-23108 9.8 An improper neutralization of special elements used in an os command ('os com... CVE-2019-16153 9.8 A hard-coded password vulnerability in the Fortinet FortiSIEM database compon...
View all Fortinet CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →