CVE-2026-39808 — Fortinet FortiSandbox OS Command Injection Vulnerability
Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
- CVSS
- 9.8 (Critical)
- KEV status
- CISA KEV — Listed
- First seen (CISA KEV)
- Recommended change window
- Emergency change — patch alongside CVE-2026-25089; single Fortinet maintenance window covers both.
- Vendor advisory
- https://fortiguard.fortinet.com/psirt/FG-IR-26-100
- Affected products
- Fortinet FortiSandbox
Why this one matters to a CAB
This is the second FortiSandbox command-injection CVE added to KEV on the same day as CVE-2026-25089 and it lives in an adjacent code path in the same HTTP management stack. Treat them as one incident, not two — the change record should reference both.
Defender’s angle
- Do one firmware update, not two: the Fortinet advisory FG-IR-26-100 lists overlapping fixed builds with FG-IR-26-141. Bundling avoids two rollback drills in one week.
- Post-patch verification: after upgrade,
diagnose test application httpsd 44on the FortiSandbox will print the running build; capture that string in the change record as proof of remediation. - Log retention: extend the FortiSandbox syslog forwarding to keep the pre-patch management-plane logs for 90 days. Investigators will need them if an incident is discovered later.
What to bring to CAB
One combined change record for CVE-2026-25089 and CVE-2026-39808, one maintenance window, one rollback snapshot. Splitting doubles the operational risk without halving the attack window.
Sources
This page summarizes publicly available information from CISA KEV, NVD, and the listed vendor advisory. Change Risk Intel does not publish exploit walkthroughs. Verify with your vendor before scheduling any change window.