What is CVE-2026-39808?
CVE-2026-39808 is an OS command injection vulnerability in Fortinet FortiSandbox that allows an unauthenticated attacker to execute unauthorized code via crafted HTTP requests. This flaw could lead to remote code execution. Fortinet users should urgently apply the updates provided by the vendor.
Azərbaycanca: CVE-2026-39808 Fortinet FortiSandbox-da autentifikasiya olunmamış hücumçunun xüsusi hazırlanmış HTTP sorğuları vasitəsilə əmr inyeksiyası həyata keçirməsinə imkan verən boşluqdur. Bu zəiflik uzaqdan kod icrasına səbəb ola bilər. Fortinet istifadəçiləri təcili olaraq istehsalçı tərəfindən təqdim edilən yeniləmələri tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-78; shared vendor: Fortinet
FAQ2
Which Fortinet product is affected by CVE-2026-39808 and what is the main risk?
This vulnerability affects the FortiSandbox product. An unauthenticated attacker can perform command injection via crafted HTTP requests, posing a risk of remote code execution (RCE).
What should be done to protect against CVE-2026-39808?
Users should urgently apply the updates provided by Fortinet.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.