What is CVE-2026-25089?
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests
Affected product
Fortinet FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS
Remediation Steps
- Apply Fortinet security patch for the command injection vulnerability in FortiSandbox WEB UI
- Review and restrict administrative access to FortiSandbox deployments
- Validate that command injection attempts are blocked or logged
- Monitor FortiSandbox logs for exploitation attempts
References
Coverage on defend.network
- Vulnerability Priority Report – Week 2 of June 2026 (June 8 – 14)
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.