Medium SEVERITY — Vulnerability

Arbitrary directory delete on vmimages delete feature

CVSSv3 Score: 6.2 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS and FortiSandbox Cloud WEB UI may allow a privileged attacker with super-admin profile and CLI access to delete an arbitrary directory via HTTP crafted requests. Revised on 2026-04-14 00:00:00

Platform
FortiGate / FortiOS
CVSS Score
6.2/10
Advisory
FG-IR-26-115
Published
14 April 2026
Views
3
Primary source: Review the official advisory at fortiguard.fortinet.com Kaynağa Git

Summary

CVSSv3 Score: 6.2 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS and FortiSandbox Cloud WEB UI may allow a privileged attacker with super-admin profile and CLI access to delete an arbitrary directory via HTTP crafted requests. Revised on 2026-04-14 00:00:00

Source

  • [Open vendor advisory](https:\/\/fortiguard.fortinet.com\/psirt\/FG-IR-26-115)

This entry was ingested automatically; verify the content before publishing.

FortiGate / FortiOS — Related Advisories

VIEW ALL →