CVE-2026-27316

LOW

Fortinet FortiSandbox <5.0.5 - Info Disclosure

Title source: llm
STIX 2.1

Description

A insufficiently protected credentials vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4 all versions, FortiSandbox PaaS 5.0.1 through 5.0.5 may allow an authenticathed administrator to read LDAP server credentials via client-side inspection.

Scores

CVSS v3 2.7
EPSS 0.0003
EPSS Percentile 10.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-522
Status published
Products (15)
Fortinet/FortiSandbox 4.4.0 - 4.4.9
fortinet/fortisandbox 4.4.0 - 5.0.6
Fortinet/FortiSandbox 5.0.0 - 5.0.5
Fortinet/FortiSandbox PaaS 21.3.4055
Fortinet/FortiSandbox PaaS 21.4.4072
Fortinet/FortiSandbox PaaS 22.1.4113
Fortinet/FortiSandbox PaaS 22.2.4134
Fortinet/FortiSandbox PaaS 22.2.4151
Fortinet/FortiSandbox PaaS 23.1.4245
Fortinet/FortiSandbox PaaS 23.3.4329
... and 5 more
Published Apr 14, 2026
Tracked Since Apr 14, 2026