Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-26083 -- CVSS 9.8 Vulnerability Briefing

CVE-2026-26083 | CVSS 9.8 (Critical) | Exploit: PoC available

What Is It

CVE-2026-26083 is a missing authorization vulnerability affecting Fortinet FortiSandbox on-premises appliances, FortiSandbox Cloud, and FortiSandbox PaaS across multiple version branches, allowing unauthenticated or unauthorized access to protected functionality.

Technical Detail

The flaw stems from absent or improperly enforced authorization checks on one or more API endpoints or functional components within FortiSandbox. An attacker who can reach the affected interface does not need valid credentials or elevated privileges to trigger the vulnerable code path, effectively bypassing access controls. Depending on the specific endpoint exposed, successful exploitation could result in unauthorized access to sandbox analysis data, configuration manipulation, or further lateral movement within environments where FortiSandbox is integrated with other Fortinet security fabric components.

Exploitation Status

A proof-of-concept exploit is publicly available as of this writing. This CVE is not currently listed in the CISA Known Exploited Vulnerabilities catalog, meaning active in-the-wild exploitation has not been formally confirmed by CISA. However, the existence of a public PoC against a critical-severity authorization bypass in a widely deployed security product significantly lowers the barrier for exploitation and warrants urgent attention.

Who Is Targeting This

No specific threat actor attribution at this time. Neither confirmed nor reported threat actor associations have been established for this vulnerability. Given the nature of the affected product and the availability of a public PoC, opportunistic actors targeting exposed Fortinet infrastructure should be considered a realistic threat.

What To Do

Organizations running FortiSandbox 5.0.0 through 5.0.1 should upgrade to a patched release as soon as Fortinet makes one available; the same applies to FortiSandbox 4.4.0 through 4.4.8. Operators of FortiSandbox Cloud versions 5.0.2 through 5.0.5 and all affected FortiSandbox PaaS branches should consult Fortinet's advisory for cloud-side remediation timelines, as patching may be partially or fully managed by the vendor. In the interim, restrict network access to FortiSandbox management interfaces using firewall rules or access control lists, ensuring only trusted administrative hosts can reach the affected endpoints. Monitor FortiSandbox logs for anomalous unauthenticated requests or unexpected API activity. Review Fortinet's official PSIRT advisory for the complete list of fixed versions and any available workarounds specific to each deployment model.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →