Critical SEVERITY — Vulnerability

Second-Order OS Command Injection via JSON Input on start vnc feature

CVSSv3 Score: 9.1 An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests. Revised on 2026-06-09 00:00:00

Platform
FortiGate / FortiOS
CVSS Score
9.1/10
Advisory
FG-IR-26-141
Published
09 June 2026
Views
3
Primary source: Review the official advisory at fortiguard.fortinet.com Kaynağa Git

Summary

CVSSv3 Score: 9.1 An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests. Revised on 2026-06-09 00:00:00

Source

This record was ingested automatically; verify the content before publication.

FortiGate / FortiOS — Related Advisories

VIEW ALL →