Unauthenticated Control of NAT Rules Leading to Exposure of Sensitive Information
FG-IR-26-166
CVSSv3 Score: 9.1 An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests. Revised on 2026-06-09 00:00:00
The publication date reported by the vendor.
We collected the advisory from the official source.
Our collector saw this advisory during a later source check.