CVE-2026-26084EPSS p30.7%
CVE-2026-26084CVE-2026-26084
Description
A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests.
Scoring
| CVSS | 9.9 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H |
| EPSS | 0.39% probability of exploitation · percentile 30.7% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-08 |