Zum Inhalt springen
CVE-2026-39808CriticalCVSS: 9.1

Kritische Schwachstelle in Fortinet FortiSandbox – OS Command Injection (CVE-2026-39808)

In Fortinet FortiSandbox 4.4.0 bis 4.4.8 existiert eine OS Command Injection-Schwachstelle über die API, die es einem nicht authentifizierten Angreifer erlaubt, unbefugten Code auszuführen. Ein Patch ist verfügbar.

METADATEN

Entdeckt:
14.04.2026
Patch verfügbar:
Ja

BETROFFENE SYSTEME

  • FortiSandbox 4.4.0
  • FortiSandbox 4.4.1
  • FortiSandbox 4.4.2
  • FortiSandbox 4.4.3
  • FortiSandbox 4.4.4
  • FortiSandbox 4.4.5
  • FortiSandbox 4.4.6
  • FortiSandbox 4.4.7
  • FortiSandbox 4.4.8
  • FortiSandbox PaaS 21.3.4055
  • FortiSandbox PaaS 21.4.4072
  • FortiSandbox PaaS 22.1.4113
  • FortiSandbox PaaS 22.2.4134
  • FortiSandbox PaaS 22.2.4151
  • FortiSandbox PaaS 23.1.4245
  • FortiSandbox PaaS 23.3.4329
  • FortiSandbox PaaS 23.4.4350
  • FortiSandbox PaaS 23.4.4374

Zusammenfassung

Eine kritische Schwachstelle der Schwereklasse Critical (CVSS 9.1) wurde in Fortinet FortiSandbox Version 4.4.0 bis 4.4.8 entdeckt. Die Schwachstelle (CWE-78) ermöglicht es einem nicht authentifizierten Angreifer über manipulierte HTTP-Anfragen an die API, beliebige Betriebssystembefehle auf dem Server auszuführen.

Die Schwachstelle wurde am 14. April 2026 veröffentlicht und unter verantwortungsvoller Offenlegung durch Samuel de Lucas Maroto (KPMG Spain) gemeldet. Es sind keine bekannten Exploits im Umlauf.

Technische Details

Eigenschaft Wert
CVE-ID CVE-2026-39808
CVSSv3-Score 9.1 (Critical)
Schwachstellart OS Command Injection (CWE-78)
Betroffene Komponente API
Angriffsvektor Netzwerk (Network)
Authentifizierung erforderlich Nein (Unauthenticated)
Bekannte Exploits Keine
Schwereklasse AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Die Schwachstelle betrifft die API-Endpunkte von FortiSandbox. Ein Angreifer kann über speziell formulierte HTTP-Andräge Shell-Befehle einschleusen, da Eingaben nicht ausreichend neutralisiert werden.

Betroffene Systeme

Betroffene Versionen:

  • FortiSandbox 4.4.0 bis 4.4.8

Nicht betroffen:

  • FortiSandbox 5.0
  • FortiSandbox PaaS 5.0

Betroffene PaaS-Versionen:

  • FortiSandbox PaaS 21.3.4055
  • FortiSandbox PaaS 21.4.4072
  • FortiSandbox PaaS 22.1.4113
  • FortiSandbox PaaS 22.2.4134
  • FortiSandbox PaaS 22.2.4151
  • FortiSandbox PaaS 23.1.4245
  • FortiSandbox PaaS 23.3.4329
  • FortiSandbox PaaS 23.4.4350
  • FortiSandbox PaaS 23.4.4374

Empfehlungen und Maßnahmen

  1. Sofortiges Update: Aktualisieren Sie FortiSandbox auf Version 4.4.9 oder höher. Dies ist der offizielle Fix von Fortinet.
  2. PaaS-Kunden: FortiSandbox PaaS 5.0 ist nicht betroffen. Für ältere PaaS-Versionen sollte ein Upgrade auf die neueste Version erfolgen.
  3. Zugriffskontrolle: Stellen Sie sicher, dass die API-Endpunkte von FortiSandbox nicht aus dem Internet erreichbar sind, bis das Update eingespielt wurde.
  4. Überwachung: Überwachen Sie Ihre Systeme auf ungewöhnliche Aktivitäten und prüfen Sie Logs auf verdächtige API-Aufrufe.

Quellen