SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-26084

CRITICAL · CVSS 9.9 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

Fortinet FortiSandbox versions 5.0.0 to 5.0.5 and 4.4.0 to 4.4.8, along with FortiSandbox Cloud and PaaS versions 5.0.4 to 5.0.5, are vulnerable due to improper access control, enabling attackers to exploit crafted HTTP requests to gain unauthorized access to sensitive information. The critical severity of this vulnerability (CVSS 9.9) necessitates immediate attention from organizations utilizing these Fortinet products, particularly those handling sensitive data. Security teams should prioritize patching or mitigating this vulnerability to prevent potential data breaches.

CVE
CVE-2026-26084
Severity
CRITICAL
CVSS
9.9
EPSS
0.24%
Fortinet

Original NVD Description

A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests.