SSRF in GUI console

Summary

A Server-Side Request Forgery (SSRF) vulnerability [CWE-918] in FortiSandbox may allow an authenticated attacker to proxy internal requests limited to plaintext endpoints only via crafted HTTP requests.

Version Affected Solution
FortiSandbox 5.0 5.0.0 through 5.0.4 Upgrade to 5.0.5 or above
FortiSandbox 4.4 4.4 all versions Migrate to a fixed release
FortiSandbox 4.2 4.2 all versions Migrate to a fixed release
FortiSandbox 4.0 4.0 all versions Migrate to a fixed release

Acknowledgement

Fortinet is pleased to thank Jason McFadyen of Trend Research working with Trend Micro Zero Day Initiative for reporting this vulnerability under responsible disclosure.

Timeline

2026-01-13: Initial publication