logo

PoC Released for FortiSandbox Flaw Enabling Arbitrary Command Execution

ID: 501ebb53-93ab-54e2-82f1-b7523bc61f6c

STIX ID: report--501ebb53-93ab-54e2-82f1-b7523bc61f6c

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-04-17

Date Updated: 2026-04-22

Author: Divya

...
...

A public proof-of-concept for CVE-2026-39808 exposes an unauthenticated remote command execution flaw in Fortinet FortiSandbox (affecting versions 4.4.0–4.4.8) via the /fortisandbox/job-detail/tracer-behavior endpoint by injecting commands through the 'jid' parameter; the exploit runs commands as root and writes output to the web root—administrators are urged to apply Fortinet's patch, review logs for suspicious GET requests, and inspect web roots for unexpected files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.