CVE-2026-25836

Publication date

2026-03-10 16:44:06

Family

fortinet

State

PUBLISHED

Description

An improper neutralization of special elements used in an os command (os command injection) vulnerability in Fortinet FortiSandbox Cloud 5.0.4 may allow a privileged attacker with super-admin profile and CLI access to execute unauthorized code or commands via crafted HTTP requests.