High SEVERITY — Vulnerability

Unauthenticated Control of NAT Rules Leading to Exposure of Sensitive Information

CVSSv3 Score: 8.9 An improper access control vulnerability in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to access sensitive information via crafted HTTP requests. Revised on 2026-09-08 00:00:00

Platform
FortiGate / FortiOS
CVSS Score
8.9/10
Advisory
FG-IR-26-166
Published
08 September 2026
Views
32
Primary source: Review the official advisory at fortiguard.fortinet.com Go to Source

Summary

CVSSv3 Score: 8.9 An improper access control vulnerability in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to access sensitive information via crafted HTTP requests. Revised on 2026-09-08 00:00:00

Source

FortiGate / FortiOS — Related Advisories

VIEW ALL →