HIGH🇵🇱 Wersja polska

CVE-2026-59835

CVSS 8.6v3.1pub. 2026-07-14upd. 2026-07-15

A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
  • Fortinet Fortisandbox

    APP
    Fortinet
    4.4.3 – 4.4.9 (excl.)5.0.0 – 5.0.3 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2026-25089CRITICAL9.8⚠ KEVPL ✓same product

Command injection w Fortinet FortiSandbox — dostęp bez uwierzytelnienia

CVE-2026-39808CRITICAL9.8⚠ KEVPL ✓same product

Command Injection w Fortinet FortiSandbox umożliwiający RCE

CVE-2026-26083CRITICAL9.8PL ✓same product

Brak autoryzacji w Fortinet FortiSandbox umożliwia zdalne wykonanie kodu

CVE-2026-39813CRITICAL9.8PL ✓same product

Path Traversal w Fortinet FortiSandbox umożliwiający privilege escalation

CVE-2025-52436HIGH8.8same product

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79]...