Unauthenticated Authentication bypass and Privilege escalation in FortiSandbox
Summary
A Path Traversal vulnerability [CWE-24] in FortiSandbox JRPC API may allow an unauthenticated attacker to bypass authentication via specially crafted HTTP requests.
| Version | Affected | Solution |
|---|---|---|
| FortiSandbox 5.2 | Not affected | Not Applicable |
| FortiSandbox 5.0 | 5.0.0 through 5.0.5 | Upgrade to 5.0.6 or above |
| FortiSandbox 4.4 | 4.4.0 through 4.4.8 | Upgrade to 4.4.9 or above |
| FortiSandbox 4.2 | Not affected | Not Applicable |
Acknowledgement
Internally discovered and reported by Loic Pantano of Fortinet PSIRTTimeline
2026-04-14: Initial publication