logo

Root Access Unlocked: FortiSandbox CVE-2026-39808 Details and PoC Exploit Publicly Disclosed

ID: 8f8cd857-fd92-5043-97dc-8ffbad33b3df

STIX ID: report--8f8cd857-fd92-5043-97dc-8ffbad33b3df

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-04-20

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical OS command injection vulnerability (CVE-2026-39808) in FortiSandbox 4.4.x permits unauthenticated attackers to achieve root remote code execution by injecting commands into the jid parameter of the /fortisandbox/job-detail/tracer-behavior endpoint; a public proof-of-concept curl command and technical details have been disclosed, Fortinet recommends upgrading vulnerable 4.4.0–4.4.8 instances to 4.4.9 or later.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.