Executive Summary

CVE-2026-84387 is a command injection flaw in the FortiSandbox write_remote_backup_to_crontab function, where an attacker-controlled cronValue parameter is passed into a system-level context without sanitization, permitting arbitrary code execution after authentication. In OT environments where FortiSandbox sits at the boundary inspecting files moving between enterprise and control networks, a compromised sandbox becomes a pivot node with visibility into both zones.

Technical Exposure Breakdown

The vulnerable component is the remote backup routine responsible for writing scheduled tasks to crontab. Independent security research assigned a CVSS rating of 7.2. The mechanism is straightforward: user-supplied input in the cronValue field is concatenated into a command or crontab entry that is later executed by the underlying scheduler. Because the injected value is not validated or escaped, an attacker who controls this field can append shell metacharacters and force execution of arbitrary commands under the privileges of the process handling the backup configuration.

Authentication is required to exploit this vulnerability. That requirement narrows the exposure but does not eliminate it. In practice, FortiSandbox administrative credentials are frequently shared across appliance fleets, stored in configuration management systems, or reused from IT authentication stores. A phished operator credential, a compromised jump host, or an over-provisioned service account converts an authenticated-only bug into a usable remote code execution path. The attack vector is the management interface, which in poorly segmented deployments remains reachable from the enterprise network rather than being isolated to a dedicated management VLAN.

The grounding data does not confirm a specific fixed version or patch status, so operators should treat all deployed FortiSandbox instances as potentially affected until vendor advisories are verified against their exact build.

OT Impact and Compliance Risk

FortiSandbox is a detonation and analysis platform. In OT architectures it is often positioned to inspect files, firmware images, and email attachments crossing from the corporate network toward the control environment. Code execution on this device means an adversary can disable detection, tamper with verdicts to pass malicious payloads as clean, or use the appliance as a staging point for lateral movement toward the industrial DMZ.

This is not a device that physically actuates a process, but its compromise degrades the integrity of the security boundary that protects devices that do. Under IEC 62443, a sandbox that spans conduits between zones is a high-consequence asset, and its compromise breaks the zone and conduit trust model directly. For NERC CIP entities, a FortiSandbox operating within or adjacent to the Electronic Security Perimeter falls under CIP-007 patch management and CIP-005 access control obligations. For pipeline operators subject to TSA SD-02C, the requirement to protect critical cyber systems and enforce network segmentation is undermined when the boundary inspection tool itself is the entry point. Water and wastewater utilities operating under AWIA 2018 risk assessments should account for the same class of boundary-device exposure.

Compensating Controls

Do not treat vendor patching as the only response. In OT contexts, appliance firmware updates require change windows and validation that can span weeks. In the interim, apply the following:

Avoid active scanning of the appliance from within the control network. Aggressive probing of the management interface or adjacent industrial components can destabilize devices that were never designed for repeated unsolicited traffic and can brick fragile field equipment. Use passive monitoring and traffic mirroring instead.

BreachSpider Intel

BreachSpider tracks CVE-2026-84387 and related boundary-device exposures across OT deployments for continuous monitoring and virtual patch guidance.