Incorrect authorization in GUI console

Summary

An incorrect authorization vulnerability [CWE-863] in FortiSandbox may allow a low priviledged administrator to execute elevated CLI commands via the GUI console menu.

Version Affected Solution
FortiSandbox 5.0 Not affected Not Applicable
FortiSandbox 4.4 4.4.0 through 4.4.6 Upgrade to 4.4.7 or above
FortiSandbox 4.2 Not affected Not Applicable
FortiSandbox 4.0 Not affected Not Applicable

Acknowledgement

Fortinet is pleased to thank Mister Thomas SAUTIER for reporting this vulnerability under responsible disclosure.

Timeline

2025-03-11: Initial publication