logo

PoC Exploit Released for FortiSandbox Vulnerability that Allows Attacker to Execute Commands

ID: ada134ff-72f3-553a-8024-9a7d97550775

STIX ID: report--ada134ff-72f3-553a-8024-9a7d97550775

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-04-18

Date Updated: 2026-04-21

Author: Abinaya

...
...

A public proof-of-concept exploit for CVE-2026-39808 enables unauthenticated OS command injection and remote code execution as root against Fortinet FortiSandbox (versions 4.4.0–4.4.8) via the /fortisandbox/job-detail/tracer-behavior endpoint; Fortinet released a patch and advisory (FG-IR-26-100) and organizations are urged to patch, audit exposed instances, review logs for suspicious GET requests to the endpoint, and restrict access to management interfaces.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.