Vulnerability Details CVE-2026-25836
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox Cloud 5.0.4 may allow a privileged attacker with super-admin profile and CLI access to execute unauthorized code or commands via crafted HTTP requests.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 36.2%
CVSS Severity
CVSS v3 Score 7.2
Products affected by CVE-2026-25836
-
cpe:2.3:a:fortinet:fortisandbox_cloud:5.0.4