A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:LFortinet Fortisandbox
APPFortinet4.4.3 – 4.4.9 (excl.)5.0.0 – 5.0.3 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
Related vulnerabilities
CVE-2026-25089CRITICAL9.8⚠ KEVPL ✓same product
Command injection w Fortinet FortiSandbox — dostęp bez uwierzytelnienia
CVE-2026-39808CRITICAL9.8⚠ KEVPL ✓same product
Command Injection w Fortinet FortiSandbox umożliwiający RCE
CVE-2026-26083CRITICAL9.8PL ✓same product
Brak autoryzacji w Fortinet FortiSandbox umożliwia zdalne wykonanie kodu
CVE-2026-39813CRITICAL9.8PL ✓same product
Path Traversal w Fortinet FortiSandbox umożliwiający privilege escalation
CVE-2025-52436HIGH8.8same product
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79]...