CVE-2026-39812 Details
Description
A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox PaaS 5.0.0 through 5.0.5, FortiSandbox PaaS 4.4.0 through 4.4.8, FortiSandbox PaaS 4.2 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>
A cross-site scripting vulnerability has been identified in Fortinet FortiSandbox versions 5.0.0 through 5.0.5, 4.4.0 through 4.4.8, and 4.2 all versions, as well as in FortiSandbox PaaS versions 5.0.0 through 5.0.5, 4.4.0 through 4.4.8, and 4.2 all versions. This vulnerability allows a privileged attacker to execute unauthorized code or commands by sending crafted HTTP requests, leading to a stored cross-site scripting attack.
Users can upgrade Fortinet FortiSandbox to version 5.0.6 or above, 4.4.9 or above, or migrate to a fixed release for FortiSandbox 4.2. Fortinet FortiSandbox PaaS users should upgrade to version 5.0.6 or above, 4.4.9 or above, or migrate to a fixed release for FortiSandbox PaaS 4.2.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-26-110 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| fortinet fortisandbox | >= 4.2.0, <= 4.2.8 >= 4.4.0, < 4.4.9 >= 5.0.0, < 5.0.6 |
CPE
Remediation
| |
| fortinet fortisandbox cloud | >= 22.2.4134, <= 23.1.4260 >= 23.3.4329, <= 24.1.4436 5.0.4 5.0.5 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 21, 2026 | Initial Analysis | [email protected] |
| Apr 14, 2026 | New CVE Received | [email protected] |