CVE 6.2 MEDIUM

CVE-2026-25691_CVE-2026-25691

6.2 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H/E:F/RL:O/RC:C

Description

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4, FortiSandbox PaaS 5.0.4 may allow a privileged attacker with super-admin profile and CLI access to delete an arbitrary directory via HTTP crafted requests.

Basic Information

ID CVE-2026-25691
Source fortinet
Published Apr 14, 2026 at 15:38

Affected Product

Vendor Fortinet
Product FortiSandbox PaaS
Version 5.0.4
Affected Versions Fortinet FortiSandbox PaaS 5.0.4
Fortinet FortiSandbox Cloud 5.0.4
Fortinet FortiSandbox 5.0.0
Fortinet FortiSandbox 4.4.0
Fortinet FortiSandbox 4.2.1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.