← All Advisories

CVE-2026-39813

Status: EPSS-IMMINENT  |  Advisory ID: CVE-2026-39813

Key Details

CVECVE-2026-39813
CVSSCVSS 9.8 (Critical).
Affected productsFortinet FortiSandbox
Classified asCWE-24 (Path Traversal: '../filedir')
Exploitation prediction (EPSS)22% probability of exploitation in the next 30 days (98% percentile) -- FIRST.org's EPSS model.

What to Know

A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially crafted HTTP requests.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-39813
Vendor advisoryhttps://fortiguard.fortinet.com/psirt/FG-IR-26-112