OS command injection on vmimages update feature

Summary

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow a privileged attacker with super-admin profile and CLI access to execute unauthorized code or commands via crafted HTTP requests.

Version Affected Solution
FortiSandbox Cloud 5.0 5.0.4 Upgrade to 5.0.5 or above
FortiSandbox Cloud 4.4 Not affected Not Applicable
FortiSandbox PaaS 23.4 Not affected Not Applicable
FortiSandbox PaaS 5.0 5.0.4 Upgrade to 5.0.5 or above
FortiSandbox PaaS 4.4 Not affected Not Applicable

Acknowledgement

Internally discovered and reported by Adham El karn of Fortinet Product Security team.

Timeline

2026-03-10: Initial publication
2026-03-26: PaaS added