VDB

CVE-2026-84387

CVE-2026-84387 PUBLISHED CVSS 6.7 MEDIUM

Reported by fortinet · Published September 8, 2026

A improper neutralization of special elements used in a command ('command injection') vulnerability in Fortinet FortiSandbox 5.2.0, FortiSandbox 5.0.0 through 5.0.6, FortiSandbox 4.4.0 through 4.4.9 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

Risk Scores

CVSS 3.1
6.7
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C

Affected Products

VendorProductVersions
FortinetFortiSandbox5.2.0, 5.0.0, 4.4.0
FortinetFortiSandbox5.2.0, 5.0.0, 4.4.0

Timeline

  • Sep 8, 2026 Coalition ESS Score
  • Sep 8, 2026 CVE Published
  • Sep 8, 2026 CVE Updated
  • Sep 9, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›