PoC Released for FortiSandbox Flaw Enabling Arbitrary Command Execution
ID: 501ebb53-93ab-54e2-82f1-b7523bc61f6c
STIX ID: report--501ebb53-93ab-54e2-82f1-b7523bc61f6c
Feed Name: GBHackers
Threat Score
A public proof-of-concept for CVE-2026-39808 exposes an unauthenticated remote command execution flaw in Fortinet FortiSandbox (affecting versions 4.4.0–4.4.8) via the /fortisandbox/job-detail/tracer-behavior endpoint by injecting commands through the 'jid' parameter; the exploit runs commands as root and writes output to the web root—administrators are urged to apply Fortinet's patch, review logs for suspicious GET requests, and inspect web roots for unexpected files.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
