PT-2026-32691 · Fortinet · Fortisandbox Paas+1

Published

2026-04-14

·

Updated

2026-04-19

·

CVE-2026-39812

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions FortiSandbox versions 5.0.0 through 5.0.5 FortiSandbox versions 4.4.0 through 4.4.8 FortiSandbox version 4.2 FortiSandbox PaaS versions 5.0.0 through 5.0.5 FortiSandbox PaaS versions 4.4.0 through 4.4.8 FortiSandbox PaaS version 4.2
Description An improper neutralization of input during web page generation, known as cross-site scripting (XSS), allows a remote attacker to execute unauthorized commands or arbitrary code.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

BDU:2026-05588
CVE-2026-39812

Affected Products

Fortisandbox
Fortisandbox Paas