Second-Order OS Command Injection via JSON Input on start vnc feature
Summary
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.
| Version | Affected | Solution |
|---|---|---|
| FortiSandbox 5.2 | Not affected | Not Applicable |
| FortiSandbox 5.0 | 5.0.0 through 5.0.5 | Upgrade to 5.0.6 or above |
| FortiSandbox 4.4 | 4.4.0 through 4.4.8 | Upgrade to 4.4.9 or above |
| FortiSandbox Cloud 5.2 | Not affected | Not Applicable |
| FortiSandbox Cloud 5.0 | 5.0.4 through 5.0.5 | Upgrade to 5.0.6 or above |
| FortiSandbox Cloud 4.4 | Not affected | Not Applicable |
| FortiSandbox PaaS 23.4 | Not affected | Not Applicable |
| FortiSandbox PaaS 5.2 | Not affected | Not Applicable |
| FortiSandbox PaaS 5.0 | 5.0.4 through 5.0.5 | Upgrade to 5.0.6 or above |
| FortiSandbox PaaS 4.4 | Not affected | Not Applicable |
Acknowledgement
Internally discovered and reported by Adham El Karn of Fortinet Product Security team.Timeline
2026-06-09: Initial publication