Vulnerability intelligence
CVE-2026-39813
A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially crafted HTTP requests.
CVSS Score
9.1
Critical
EPSS — Exploit Probability
23%
Riskier than 98% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
Patch available
Vendor fix published
5 articles across 4 outlets · first covered Apr 15, 2026 · latest Jun 17, 2026
Coverage timeline
-
FortiSandbox CVE-2026-39813 lets hackers bypass auth, run codesocradar.io · Jun 17, 2026
-
3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker Crosshairswww.securityweek.com · Jun 17, 2026
-
Fortinet warns of active exploits in unpatched FortiSandbox flawssecurityaffairs.com · Jun 16, 2026
-
Exploiters target SAP SQLi and Adobe zero day flaws in Aprilthehackernews.com · Apr 15, 2026
-
Fortinet patches critical FortiSandbox flaws and high risk Cloud bugswww.securityweek.com · Apr 15, 2026