Unauthenticated Authentication bypass and Privilege escalation in FortiSandbox

Summary

A Path Traversal vulnerability [CWE-24] in FortiSandbox JRPC API may allow an unauthenticated attacker to bypass authentication via specially crafted HTTP requests.

Version Affected Solution
FortiSandbox 5.2 Not affected Not Applicable
FortiSandbox 5.0 5.0.0 through 5.0.5 Upgrade to 5.0.6 or above
FortiSandbox 4.4 4.4.0 through 4.4.8 Upgrade to 4.4.9 or above
FortiSandbox 4.2 Not affected Not Applicable

Acknowledgement

Internally discovered and reported by Loic Pantano of Fortinet PSIRT

Timeline

2026-04-14: Initial publication