CVE-2026-26083 -- CVSS 9.8 Vulnerability Briefing
CVE-2026-26083 | CVSS 9.8 (Critical) | Exploit: PoC available
What Is It
CVE-2026-26083 is a missing authorization vulnerability affecting Fortinet FortiSandbox on-premises appliances, FortiSandbox Cloud, and FortiSandbox PaaS across multiple version branches, allowing unauthenticated or unauthorized access to protected functionality.
Technical Detail
The flaw stems from absent or improperly enforced authorization checks on one or more API endpoints or functional components within FortiSandbox. An attacker who can reach the affected interface does not need valid credentials or elevated privileges to trigger the vulnerable code path, effectively bypassing access controls. Depending on the specific endpoint exposed, successful exploitation could result in unauthorized access to sandbox analysis data, configuration manipulation, or further lateral movement within environments where FortiSandbox is integrated with other Fortinet security fabric components.
Exploitation Status
A proof-of-concept exploit is publicly available as of this writing. This CVE is not currently listed in the CISA Known Exploited Vulnerabilities catalog, meaning active in-the-wild exploitation has not been formally confirmed by CISA. However, the existence of a public PoC against a critical-severity authorization bypass in a widely deployed security product significantly lowers the barrier for exploitation and warrants urgent attention.
Who Is Targeting This
No specific threat actor attribution at this time. Neither confirmed nor reported threat actor associations have been established for this vulnerability. Given the nature of the affected product and the availability of a public PoC, opportunistic actors targeting exposed Fortinet infrastructure should be considered a realistic threat.
What To Do
Organizations running FortiSandbox 5.0.0 through 5.0.1 should upgrade to a patched release as soon as Fortinet makes one available; the same applies to FortiSandbox 4.4.0 through 4.4.8. Operators of FortiSandbox Cloud versions 5.0.2 through 5.0.5 and all affected FortiSandbox PaaS branches should consult Fortinet's advisory for cloud-side remediation timelines, as patching may be partially or fully managed by the vendor. In the interim, restrict network access to FortiSandbox management interfaces using firewall rules or access control lists, ensuring only trusted administrative hosts can reach the affected endpoints. Monitor FortiSandbox logs for anomalous unauthenticated requests or unexpected API activity. Review Fortinet's official PSIRT advisory for the complete list of fixed versions and any available workarounds specific to each deployment model.