Status: EPSS-IMMINENT | Advisory ID: CVE-2026-39813
| CVE | CVE-2026-39813 |
| CVSS | CVSS 9.8 (Critical). |
| Affected products | Fortinet FortiSandbox |
| Classified as | CWE-24 (Path Traversal: '../filedir') |
| Exploitation prediction (EPSS) | 22% probability of exploitation in the next 30 days (98% percentile) -- FIRST.org's EPSS model. |
A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially crafted HTTP requests.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-39813 |
| Vendor advisory | https://fortiguard.fortinet.com/psirt/FG-IR-26-112 |