Security Advisory

CVE-2026-25836

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-03-10 16:44:06
Last updated 2026-05-12 16:54:09
Assigner fortinet
State PUBLISHED

Description

An improper neutralization of special elements used in an os command (os command injection) vulnerability in Fortinet FortiSandbox Cloud 5.0.4, FortiSandbox PaaS 5.0.4 may allow a privileged attacker with super-admin profile and CLI access to execute unauthorized code or commands via crafted HTTP requests.