CVE-2026-39812

MEDIUM

FortiSandbox 4.2-5.0.5 - Cross-Site Scripting

Title source: llm
STIX 2.1

Description

A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox PaaS 5.0.0 through 5.0.5, FortiSandbox PaaS 4.4.0 through 4.4.8, FortiSandbox PaaS 4.2 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>

References (1)

Core 1

Scores

CVSS v3 4.8
EPSS 0.0003
EPSS Percentile 10.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (10)
fortinet/fortisandbox 4.2.0 - 4.2.8
Fortinet/FortiSandbox 4.2.1 - 4.2.8
Fortinet/FortiSandbox 4.4.0 - 4.4.8
Fortinet/FortiSandbox 5.0.0 - 5.0.4
Fortinet/FortiSandbox PaaS 4.2.1 - 4.2.8
Fortinet/FortiSandbox PaaS 4.4.0 - 4.4.8
Fortinet/FortiSandbox PaaS 5.0.0 - 5.0.5
fortinet/fortisandbox_cloud 5.0.4
fortinet/fortisandbox_cloud 5.0.5
fortinet/fortisandbox_cloud 22.2.4134 - 23.1.4260
Published Apr 14, 2026
Tracked Since Apr 14, 2026