CVE-2026-39808
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized co...
Affects 1 product across 1 vendor.
Attacker injects OS commands through application inputs passed to system() or equivalent calls, leading to arbitrary command execution.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
{ "executive_summary": "A critical vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 allows attackers to execute unauthorized code or commands due to improper neutralization of special elements used in an OS command, leading to potential full system compromise.", "attack_vector_detail": "The vulnerability arises from the improper handling of user input, which can be manipulated to inject malicious OS commands. An attacker could exploit this by sending specially crafted input to the affected system, potentially leading to remote code execution.", "affected_components": ["FortiSandbox 4.4.0", "FortiSandbox 4.4.1", "FortiSandbox 4.4.2", "FortiSandbox 4.4.3", "FortiSandbox 4.4.4", "FortiSandbox 4.4.5", "FortiSandbox 4.4.6", "FortiSandbox 4.4.7", "FortiSandbox 4.4.8"], "exploitation_likelihood": "CRITICAL", "remediation_priority": "IMMEDIATE", "confidence": "
BSID: BS-2026-GLOBAL-074734-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2026-39808?
What is the CVSS score for CVE-2026-39808?
Is CVE-2026-39808 actively exploited?
How do I remediate CVE-2026-39808?
What systems are affected by CVE-2026-39808?
| CVE ID | CVE-2026-39808 |
|---|---|
| BSID | BS-2026-GLOBAL-074734-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Published | 2026-04-14 |
| Last Modified | 2026-04-22 |
| ICS Relevance | 70% |
| Weakness (CWE) | |
| Domains | |
| Source | NVD |
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>
Source: NIST NVD / MITRE CVE Database
Vulnerability details: A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
Exploitation Likelihood: MEDIUM
| Vendor | Product | Fixed Version |
|---|---|---|
| Fortinet | Fortisandbox | — |
| CISA KEV | ● Active Exploitation Confirmed (added 2026-07-16) |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | MEDIUM |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | d4b7fe86babe1543f1638c954f0b2e626ceedd842a4830479c3b6e67a889cae6a0f38b564a0789181ff71c6629a6a58e3bd87c4f2d2e02c2b347130e55f09dad |
This Vulnerability Is Being Actively Exploited
CVE-2026-39808 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider alerts your team within 15 minutes when KEV vulnerabilities match your ICS assets.
Start Free KEV Monitoring →