CVE-2026-39808

● KEV CRITICAL

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized co...

Affects 1 product across 1 vendor.

BCS8.31
CVSS 3.19.8
EPSS89.7%
Percentile100th
PatchPatched
KEV Added2026-07-16
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-78: OS Command Injection

Attacker injects OS commands through application inputs passed to system() or equivalent calls, leading to arbitrary command execution.

Related Attack Patterns (CAPEC)
CAPEC-43 Exploiting Multiple Input Interpretation Layers
via CWE-78
CAPEC-108 Command Line Execution through SQL Injection
via CWE-78
CAPEC-6 Argument Injection
via CWE-78
CAPEC-15 Command Delimiters
via CWE-78
CAPEC-88 OS Command Injection
via CWE-78

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

{ "executive_summary": "A critical vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 allows attackers to execute unauthorized code or commands due to improper neutralization of special elements used in an OS command, leading to potential full system compromise.", "attack_vector_detail": "The vulnerability arises from the improper handling of user input, which can be manipulated to inject malicious OS commands. An attacker could exploit this by sending specially crafted input to the affected system, potentially leading to remote code execution.", "affected_components": ["FortiSandbox 4.4.0", "FortiSandbox 4.4.1", "FortiSandbox 4.4.2", "FortiSandbox 4.4.3", "FortiSandbox 4.4.4", "FortiSandbox 4.4.5", "FortiSandbox 4.4.6", "FortiSandbox 4.4.7", "FortiSandbox 4.4.8"], "exploitation_likelihood": "CRITICAL", "remediation_priority": "IMMEDIATE", "confidence": "

BSID: BS-2026-GLOBAL-074734-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-39808?
{ "executive_summary": "A critical vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 allows attackers to execute unauthorized code or commands due to improper neutralization of special elements used in an OS command, leading to potential full system compromise.", "attack_vector_detail": "The vulnerability arises from the improper handling of user input, which can be manipulated to inject malicious OS commands. An attacker could exploit this by sending specially crafted input to the
What is the CVSS score for CVE-2026-39808?
CVE-2026-39808 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 89.7%.
Is CVE-2026-39808 actively exploited?
Yes. CVE-2026-39808 is in the CISA KEV catalog (added 2026-07-16). Active exploitation confirmed. Immediate patching required.
How do I remediate CVE-2026-39808?
Priority: HIGH. Advisory: https://fortiguard.fortinet.com/psirt/FG-IR-26-100 PSIRT: [email protected]
What systems are affected by CVE-2026-39808?
CVE-2026-39808 affects: Fortinet.
Vulnerability Details
CVE IDCVE-2026-39808
BSIDBS-2026-GLOBAL-074734-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2026-04-14
Last Modified2026-04-22
ICS Relevance70%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Fortinet Fortisandbox
Remediation
View Vendor Advisory →

Remediation Priority: HIGH

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 102 Days
CISA KEV● Active Exploitation Confirmed (added 2026-07-16)
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hashd4b7fe86babe1543f1638c954f0b2e626ceedd842a4830479c3b6e67a889cae6a0f38b564a0789181ff71c6629a6a58e3bd87c4f2d2e02c2b347130e55f09dad
Related CVEs affecting Fortinet
CVE-2005-3057 10.0 The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and ot... CVE-2024-47575 9.8 A missing authentication for critical function in FortiManager 7.6.0, FortiMa... CVE-2024-23109 9.8 An improper neutralization of special elements used in an os command ('os com... CVE-2024-23108 9.8 An improper neutralization of special elements used in an os command ('os com... CVE-2019-16153 9.8 A hard-coded password vulnerability in the Fortinet FortiSIEM database compon...
View all Fortinet CVEs →

This Vulnerability Is Being Actively Exploited

CVE-2026-39808 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider alerts your team within 15 minutes when KEV vulnerabilities match your ICS assets.

Start Free KEV Monitoring →