Threat reportVulnerabilityTL-2026-0823

FortiSandbox Unauthenticated RCE Chain: JRPC API Path-Traversal Auth Bypass and OS Command Injection (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089)

criticalACTIVE

FortiSandbox Unauthenticated RCE Chain (TL-2026-0823) is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-06-16. It has no confirmed attribution, affects Fortinet FortiSandbox 4.4, references 3 CVEs (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089), maps to 14 MITRE ATT&CK techniques (T1005, T1007, T1059), and is covered by 9 detection rules and 15 indicators of compromise.

CVSS
9.8/10Critical
CVEs
3Referenced vulnerabilities
Techniques
14MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
15Indicators of compromise

Key facts for TL-2026-0823

Threat ID
TL-2026-0823
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
financial, government, technology, managed-security-services
Target regions
Middle East, Global
Detection rules
9
Indicators of compromise
15

Malware and tooling in FortiSandbox Unauthenticated RCE Chain

Malware and tooling: AI-generated ('vibecoded') CVE-2026-25089 exploit

How FortiSandbox Unauthenticated RCE Chain works

Three critical FortiSandbox flaws enable unauthenticated remote code execution on a malware-analysis security appliance: a JRPC API path-traversal authentication bypass (CVE-2026-39813), an OS command injection on the tracer-behavior API endpoint (CVE-2026-39808), and a second-order OS command injection in the web UI 'start vnc' feature affecting FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS (CVE-2026-25089). Fortinet patched the first two on 14 Apr 2026 (FG-IR-26-100, FG-IR-26-112) and the third on 9 Jun 2026 (FG-IR-26-141); Defused observed in-the-wild exploitation attempts across all three within a 24-hour window on 15-16 Jun 2026, including an AI-generated ('vibecoded') and likely faulty exploit for CVE-2026-25089.

FortiSandbox is Fortinet's network sandbox / detonation appliance used by SOCs to detonate suspicious files and URLs and render malware verdicts. Three vulnerabilities disclosed in 2026 combine to give a remote, unauthenticated attacker root-level code execution on the appliance itself — turning a defensive control into an attacker foothold and giving the adversary the ability to read, suppress, or poison malware verdicts.

CVE-2026-39813 (FG-IR-26-112, CWE-24/CWE-22 path traversal, CVSS 9.1 per Fortinet / 9.8 per NVD) is an authentication bypass in the JRPC API. The /jsonrpc/ endpoint is whitelisted in the Django middleware, so it skips the Layer-1 web authentication; Layer-2 session validation in is_valid_session() passes a user-controlled 'session' value straight into os.path.join(DIRRPCSESS, session_id) with no sanitization. Because Python's os.path.join() preserves leading '..' components, a payload of "session": "../../tmp/" resolves /usr/rpcsess/../../tmp/ to /tmp/ — a directory that always exists and whose modification time is continuously refreshed by system processes, satisfying the only two checks the validator performs (path exists, mtime within 3600s). The attacker thereby impersonates a privileged JRPC session without credentials and can invoke read methods such as sys/status (system information, 26 fields), sys/system_resource, config/scan/options, and backup/config (a ~32KB encrypted system backup).

CVE-2026-39808 (FG-IR-26-100, CWE-78 OS command injection, CVSS 9.1 per Fortinet / 9.8 per NVD) lives in an API endpoint that improperly neutralizes special elements. A public PoC targets the GET endpoint /fortisandbox/job-detail/tracer-behavior, injecting shell commands through the unsanitized 'jid' parameter using pipe characters — e.g. jid=|(id > /web/ng/out.txt)| — with output redirected into the web root (/web/ng/) for later HTTP retrieval. Commands execute with the privileges of the sandbox service (reported as root). Chained with CVE-2026-39813, an attacker can pivot from authentication bypass to full unauthenticated RCE.

CVE-2026-25089 (FG-IR-26-141, CWE-78, CVSS 9.1) is a second-order OS command injection via JSON input on the 'start vnc' feature in the web UI, allowing an unauthenticated attacker to execute unauthorized commands via crafted HTTP requests. It affects FortiSandbox 4.2 (all), 4.4.0-4.4.8, 5.0.0-5.0.5, and FortiSandbox Cloud/PaaS 5.0.4-5.0.5; it was disclosed on 9 Jun 2026, roughly a week before the active-exploitation reporting, and was credited to Adham El Karn of the Fortinet Product Security team.

Fortinet released fixes in FortiSandbox 4.4.9 and 5.0.6. As of mid-June 2026 the CVEs were not yet listed in the CISA KEV catalog and Fortinet had not formally confirmed in-the-wild compromise, but Defused/Defused-Cyber honeypot telemetry reported active exploitation attempts of all three within a single 24-hour window, with at least one CVE-2026-25089 exploit showing signs of AI ('vibecoded') authorship and being likely faulty. FortiSandbox vulnerabilities have not historically been a common attacker target, so the surge represents a notable shift. Because the appliance is a security control, post-patch hunting must include reviewing JRPC API access logs and the web UI for /jsonrpc/ requests containing '../', unusual command patterns on the tracer-behavior endpoint, suspicious files in /web/ng/, and re-validation of recent sandbox file verdicts.

MITRE ATT&CK techniques used in TL-2026-0823

Collection

T1005 Data from Local System

Discovery

T1007 System Service Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery

Execution

T1059 Command and Scripting Interpreter

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Initial Access

T1190 Exploit Public-Facing Application

Defense Evasion

T1211 Exploitation for Stealth

Credential Access

T1212 Exploitation for Credential Access

Persistence

T1505 Server Software Component

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1587 Develop Capabilities

Reconnaissance

T1595 Active Scanning

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in FortiSandbox Unauthenticated RCE Chain

  • Fortinet — FortiSandbox 4.4
    Vulnerable versions: 4.4.0; 4.4.1; 4.4.2; 4.4.3; 4.4.4; 4.4.5; 4.4.6; 4.4.7; 4.4.8
    Fixed in: 4.4.9
  • Fortinet — FortiSandbox 5.0
    Vulnerable versions: 5.0.0; 5.0.1; 5.0.2; 5.0.3; 5.0.4; 5.0.5
    Fixed in: 5.0.6
  • Fortinet — FortiSandbox 4.2
    Vulnerable versions: 4.2 (all versions, CVE-2026-25089)
    Fixed in: Migrate to a fixed 4.4 or 5.0 release
  • Fortinet — FortiSandbox Cloud 5.0
    Vulnerable versions: 5.0.4; 5.0.5
    Fixed in: 5.0.6
  • Fortinet — FortiSandbox PaaS 5.0
    Vulnerable versions: 5.0.4; 5.0.5
    Fixed in: 5.0.6

Remediation for FortiSandbox Unauthenticated RCE Chain

Patches

  • FortiSandbox 4.4.9 (FG-IR-26-100, FG-IR-26-112, FG-IR-26-141)
  • FortiSandbox 5.0.6 (FG-IR-26-112, FG-IR-26-141)

Immediate actions

  • Upgrade FortiSandbox to 4.4.9+ or 5.0.6+; migrate affected FortiSandbox Cloud/PaaS 5.0.4-5.0.5 instances to fixed 5.0.6 releases
  • Restrict network access to the FortiSandbox management interface, JRPC API (/jsonrpc/), and web UI to trusted management networks only; never expose to the internet
  • Hunt JRPC API access logs for /jsonrpc/ requests whose JSON body contains '../' or a 'session' value with path-traversal sequences
  • Search the web root /web/ng/ for unexpected files (e.g. out.txt) indicating CVE-2026-39808 command-injection output staging

Workarounds

  • Disable or firewall the JRPC API and web UI from untrusted networks until patching is complete
  • Block external HTTP/HTTPS access to /fortisandbox/job-detail/tracer-behavior and /jsonrpc/ at the perimeter

Longer-term hardening

  • Place security-management appliances behind a jump host / PAM with MFA and segment them from general user networks
  • Re-validate sandbox file verdicts produced before patching, as a compromised appliance could suppress or poison malware detection
  • Deploy WAF / IPS signatures for pipe-character injection on the tracer-behavior endpoint and path traversal on /jsonrpc/
  • Add FortiSandbox to the asset inventory and continuous external-attack-surface monitoring (e.g. runZero query os:="Fortinet FortiSandbox%")

CVEs associated with FortiSandbox Unauthenticated RCE Chain

CVE-2026-39813, CVE-2026-39808, CVE-2026-25089

Weaknesses (CWE) in FortiSandbox Unauthenticated RCE Chain

CWE-78, CWE-22, CWE-24

Timeline of FortiSandbox Unauthenticated RCE Chain

  • Defenders are advised to review FortiSandbox JRPC API access logs from this date onward as the earliest suspected probing window (per Fyntralink incident guidance).
  • Fortinet publishes FG-IR-26-100 (CVE-2026-39808 OS command injection) and FG-IR-26-112 (CVE-2026-39813 JRPC API path-traversal auth bypass), releasing fixes in FortiSandbox 4.4.9 and 5.0.6.
  • Help Net Security reports the April FortiSandbox disclosures (CVE-2026-39813, CVE-2026-39808), both rated critical.
  • Greenbone publishes analysis and authenticated detection coverage for the April FortiSandbox RCE vulnerabilities (CVE-2026-39813, CVE-2026-39808) via its enterprise vulnerability tests.
  • NVD last-modifies the CVE-2026-39808 record (CWE-78, CVSS 9.8), referencing FG-IR-26-100 and a public GitHub PoC.
  • Fortinet publishes FG-IR-26-141 (CVE-2026-25089), a second-order OS command injection via the web UI 'start vnc' feature affecting FortiSandbox, Cloud, and PaaS; credited to Adham El Karn of Fortinet Product Security.
  • Defused honeypot telemetry observes in-the-wild exploitation attempts across all three FortiSandbox CVEs within a 24-hour window, including an AI-authored ('vibecoded'), likely faulty exploit for CVE-2026-25089.
  • runZero and Sangfor FarSight Labs publish asset-discovery and technical deep-dive guidance to help defenders locate exposed FortiSandbox appliances (e.g. runZero query os:="Fortinet FortiSandbox%") and dissect the CVE-2026-39813 path-traversal / is_valid_session() bypass mechanics.
  • Help Net Security, BleepingComputer, and The Hacker News report active exploitation attempts; a public PoC for CVE-2026-39808 is available on GitHub. Fortinet has not formally confirmed compromise and the CVEs are not yet in the CISA KEV catalog.

Sources cited for FortiSandbox Unauthenticated RCE Chain

Detection coverage for TL-2026-0823

As of 2026-06-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0823 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
15 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats