CVE-2026-59835

HIGH

Fortinet FortiSandbox - Exposure of Resource to Wrong Sphere

Title source: rule
STIX 2.1

Description

A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests.

References (1)

Core 1

Scores

CVSS v3 8.6
EPSS 0.0046
EPSS Percentile 37.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-668
Status published
Products (3)
Fortinet/FortiSandbox 4.4.3 - 4.4.8
fortinet/fortisandbox 4.4.3 - 4.4.9
Fortinet/FortiSandbox 5.0.0 - 5.0.2
Published Jul 14, 2026
Tracked Since Jul 14, 2026