VDB
CVE-2026-59835
CVE-2026-59835
PUBLISHED
CVSS 7.7 HIGH
Reported by fortinet · Published July 14, 2026
A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests.
Risk Scores
CVSS 3.1
7.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L/E:P/RL:O/RC:C
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | FortiSandbox | 5.0.0, 4.4.3 |
| Fortinet | FortiSandbox | 5.0.0, 4.4.3, 5.0.0 |
Timeline
- Jul 14, 2026 Coalition ESS Score
- Jul 14, 2026 CVE Published
- Jul 15, 2026 Security Advisory
- Aug 7, 2026 EPSS Score