CVE-2026-26084

CRITICAL

A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5...

Affects 0 products across 1 vendor.

CVSS 3.19.9
EPSS0.4%
Percentile31th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full availability impact.
CWE Weakness Definitions
CWE-284: Improper Access Control

Software does not restrict or incorrectly restricts access to a resource.

Related Attack Patterns (CAPEC)
CAPEC-478 Modification of Windows Service Configuration
via CWE-284
CAPEC-479 Malicious Root Certificate
via CWE-284
CAPEC-546 Incomplete Data Deletion in a Multi-Tenant Environment
via CWE-284
CAPEC-550 Install New Service
via CWE-284
CAPEC-551 Modify Existing Service
via CWE-284
Show all 17

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ AI Analysis — automated analysis, not human-reviewed

A critical severity vulnerability (CVE-2026-26084) affects the target system. A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information v...

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-26084?
A critical severity vulnerability (CVE-2026-26084) affects the target system. A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information v...
What is the CVSS score for CVE-2026-26084?
CVE-2026-26084 has CVSS 9.9 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H. EPSS: 0.4%.
Is CVE-2026-26084 actively exploited?
No confirmed active exploitation of CVE-2026-26084 as of 2026-10-06.
How do I remediate CVE-2026-26084?
Apply vendor patches for CVE-2026-26084. Monitor Fortinet advisories.
What systems are affected by CVE-2026-26084?
CVE-2026-26084 affects: Fortinet.
Vulnerability Details
CVE IDCVE-2026-26084
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H
Published2026-09-08
Last Modified2026-09-08
ICS Relevance70%
Weakness (CWE)
SourceNVD
Official Description

A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests.

Source: NIST NVD / MITRE CVE Database

Affected Products
VendorProductAffected Versions
Fortinet — —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: October 2026 | Threat Age: 27 Days
CISA known-exploitedNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
Related CVEs affecting Fortinet
CVE-2005-3057 10.0 The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and ot... CVE-2025-59718 9.8 A improper verification of cryptographic signature vulnerability in Fortinet ... CVE-2025-64446 9.8 A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.... CVE-2017-17539 9.8 The presence of a hardcoded account in Fortinet FortiWLC 7.0.11 and earlier a... CVE-2018-13379 9.8 An Improper Limitation of a Pathname to a Restricted Directory ("Path Travers...
View all Fortinet CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.9 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Create a free account →