Second-Order OS Command Injection via JSON Input on start vnc feature

Summary

An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.

Version Affected Solution
FortiSandbox 5.2 Not affected Not Applicable
FortiSandbox 5.0 5.0.0 through 5.0.5 Upgrade to 5.0.6 or above
FortiSandbox 4.4 4.4.0 through 4.4.8 Upgrade to 4.4.9 or above
FortiSandbox Cloud 5.2 Not affected Not Applicable
FortiSandbox Cloud 5.0 5.0.4 through 5.0.5 Upgrade to 5.0.6 or above
FortiSandbox Cloud 4.4 Not affected Not Applicable
FortiSandbox PaaS 23.4 Not affected Not Applicable
FortiSandbox PaaS 5.2 Not affected Not Applicable
FortiSandbox PaaS 5.0 5.0.4 through 5.0.5 Upgrade to 5.0.6 or above
FortiSandbox PaaS 4.4 Not affected Not Applicable

Acknowledgement

Internally discovered and reported by Adham El Karn of Fortinet Product Security team.

Timeline

2026-06-09: Initial publication