PoC Exploit Released for FortiSandbox Vulnerability that Allows attacker to execute commands
ID: cfc078c7-544a-59be-8ee2-cb17497b47da
STIX ID: report--cfc078c7-544a-59be-8ee2-cb17497b47da
Feed Name: Cyber Press
Threat Score
A public proof-of-concept exploit for a critical FortiSandbox vulnerability (CVE-2026-39808) enables unauthenticated root remote command execution by injecting commands into the jid parameter of the /fortisandbox/job-detail/tracer-behavior endpoint; FortiSandbox 4.4.0–4.4.8 are confirmed vulnerable, a vendor patch exists outside that range, and organizations are advised to patch immediately, restrict access, and monitor for exploitation attempts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
