Threat reportVulnerabilityTL-2026-0823
FortiSandbox Unauthenticated RCE Chain: JRPC API Path-Traversal Auth Bypass and OS Command Injection (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089)
FortiSandbox Unauthenticated RCE Chain (TL-2026-0823) is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-06-16. It has no confirmed attribution, affects Fortinet FortiSandbox 4.4, references 3 CVEs (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089), maps to 14 MITRE ATT&CK techniques (T1005, T1007, T1059), and is covered by 9 detection rules and 15 indicators of compromise.
- CVSS
- 9.8/10Critical
- CVEs
- 3Referenced vulnerabilities
- Techniques
- 14MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 15Indicators of compromise
Key facts for TL-2026-0823
- Threat ID
- TL-2026-0823
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- financial, government, technology, managed-security-services
- Target regions
- Middle East, Global
- Detection rules
- 9
- Indicators of compromise
- 15
Malware and tooling in FortiSandbox Unauthenticated RCE Chain
Malware and tooling: AI-generated ('vibecoded') CVE-2026-25089 exploit
How FortiSandbox Unauthenticated RCE Chain works
Three critical FortiSandbox flaws enable unauthenticated remote code execution on a malware-analysis security appliance: a JRPC API path-traversal authentication bypass (CVE-2026-39813), an OS command injection on the tracer-behavior API endpoint (CVE-2026-39808), and a second-order OS command injection in the web UI 'start vnc' feature affecting FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS (CVE-2026-25089). Fortinet patched the first two on 14 Apr 2026 (FG-IR-26-100, FG-IR-26-112) and the third on 9 Jun 2026 (FG-IR-26-141); Defused observed in-the-wild exploitation attempts across all three within a 24-hour window on 15-16 Jun 2026, including an AI-generated ('vibecoded') and likely faulty exploit for CVE-2026-25089.
FortiSandbox is Fortinet's network sandbox / detonation appliance used by SOCs to detonate suspicious files and URLs and render malware verdicts. Three vulnerabilities disclosed in 2026 combine to give a remote, unauthenticated attacker root-level code execution on the appliance itself — turning a defensive control into an attacker foothold and giving the adversary the ability to read, suppress, or poison malware verdicts.
CVE-2026-39813 (FG-IR-26-112, CWE-24/CWE-22 path traversal, CVSS 9.1 per Fortinet / 9.8 per NVD) is an authentication bypass in the JRPC API. The /jsonrpc/ endpoint is whitelisted in the Django middleware, so it skips the Layer-1 web authentication; Layer-2 session validation in is_valid_session() passes a user-controlled 'session' value straight into os.path.join(DIRRPCSESS, session_id) with no sanitization. Because Python's os.path.join() preserves leading '..' components, a payload of "session": "../../tmp/" resolves /usr/rpcsess/../../tmp/ to /tmp/ — a directory that always exists and whose modification time is continuously refreshed by system processes, satisfying the only two checks the validator performs (path exists, mtime within 3600s). The attacker thereby impersonates a privileged JRPC session without credentials and can invoke read methods such as sys/status (system information, 26 fields), sys/system_resource, config/scan/options, and backup/config (a ~32KB encrypted system backup).
CVE-2026-39808 (FG-IR-26-100, CWE-78 OS command injection, CVSS 9.1 per Fortinet / 9.8 per NVD) lives in an API endpoint that improperly neutralizes special elements. A public PoC targets the GET endpoint /fortisandbox/job-detail/tracer-behavior, injecting shell commands through the unsanitized 'jid' parameter using pipe characters — e.g. jid=|(id > /web/ng/out.txt)| — with output redirected into the web root (/web/ng/) for later HTTP retrieval. Commands execute with the privileges of the sandbox service (reported as root). Chained with CVE-2026-39813, an attacker can pivot from authentication bypass to full unauthenticated RCE.
CVE-2026-25089 (FG-IR-26-141, CWE-78, CVSS 9.1) is a second-order OS command injection via JSON input on the 'start vnc' feature in the web UI, allowing an unauthenticated attacker to execute unauthorized commands via crafted HTTP requests. It affects FortiSandbox 4.2 (all), 4.4.0-4.4.8, 5.0.0-5.0.5, and FortiSandbox Cloud/PaaS 5.0.4-5.0.5; it was disclosed on 9 Jun 2026, roughly a week before the active-exploitation reporting, and was credited to Adham El Karn of the Fortinet Product Security team.
Fortinet released fixes in FortiSandbox 4.4.9 and 5.0.6. As of mid-June 2026 the CVEs were not yet listed in the CISA KEV catalog and Fortinet had not formally confirmed in-the-wild compromise, but Defused/Defused-Cyber honeypot telemetry reported active exploitation attempts of all three within a single 24-hour window, with at least one CVE-2026-25089 exploit showing signs of AI ('vibecoded') authorship and being likely faulty. FortiSandbox vulnerabilities have not historically been a common attacker target, so the surge represents a notable shift. Because the appliance is a security control, post-patch hunting must include reviewing JRPC API access logs and the web UI for /jsonrpc/ requests containing '../', unusual command patterns on the tracer-behavior endpoint, suspicious files in /web/ng/, and re-validation of recent sandbox file verdicts.
MITRE ATT&CK techniques used in TL-2026-0823
Collection
Discovery
T1007 System Service Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery
Execution
T1059 Command and Scripting Interpreter
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Initial Access
T1190 Exploit Public-Facing Application
Defense Evasion
T1211 Exploitation for Stealth
Credential Access
T1212 Exploitation for Credential Access
Persistence
T1505 Server Software Component
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
Reconnaissance
defense-impairment
Affected products and versions in FortiSandbox Unauthenticated RCE Chain
- Fortinet — FortiSandbox 4.4
Vulnerable versions: 4.4.0; 4.4.1; 4.4.2; 4.4.3; 4.4.4; 4.4.5; 4.4.6; 4.4.7; 4.4.8
Fixed in: 4.4.9 - Fortinet — FortiSandbox 5.0
Vulnerable versions: 5.0.0; 5.0.1; 5.0.2; 5.0.3; 5.0.4; 5.0.5
Fixed in: 5.0.6 - Fortinet — FortiSandbox 4.2
Vulnerable versions: 4.2 (all versions, CVE-2026-25089)
Fixed in: Migrate to a fixed 4.4 or 5.0 release - Fortinet — FortiSandbox Cloud 5.0
Vulnerable versions: 5.0.4; 5.0.5
Fixed in: 5.0.6 - Fortinet — FortiSandbox PaaS 5.0
Vulnerable versions: 5.0.4; 5.0.5
Fixed in: 5.0.6
Remediation for FortiSandbox Unauthenticated RCE Chain
Patches
- FortiSandbox 4.4.9 (FG-IR-26-100, FG-IR-26-112, FG-IR-26-141)
- FortiSandbox 5.0.6 (FG-IR-26-112, FG-IR-26-141)
Immediate actions
- Upgrade FortiSandbox to 4.4.9+ or 5.0.6+; migrate affected FortiSandbox Cloud/PaaS 5.0.4-5.0.5 instances to fixed 5.0.6 releases
- Restrict network access to the FortiSandbox management interface, JRPC API (/jsonrpc/), and web UI to trusted management networks only; never expose to the internet
- Hunt JRPC API access logs for /jsonrpc/ requests whose JSON body contains '../' or a 'session' value with path-traversal sequences
- Search the web root /web/ng/ for unexpected files (e.g. out.txt) indicating CVE-2026-39808 command-injection output staging
Workarounds
- Disable or firewall the JRPC API and web UI from untrusted networks until patching is complete
- Block external HTTP/HTTPS access to /fortisandbox/job-detail/tracer-behavior and /jsonrpc/ at the perimeter
Longer-term hardening
- Place security-management appliances behind a jump host / PAM with MFA and segment them from general user networks
- Re-validate sandbox file verdicts produced before patching, as a compromised appliance could suppress or poison malware detection
- Deploy WAF / IPS signatures for pipe-character injection on the tracer-behavior endpoint and path traversal on /jsonrpc/
- Add FortiSandbox to the asset inventory and continuous external-attack-surface monitoring (e.g. runZero query os:="Fortinet FortiSandbox%")
CVEs associated with FortiSandbox Unauthenticated RCE Chain
CVE-2026-39813, CVE-2026-39808, CVE-2026-25089
Weaknesses (CWE) in FortiSandbox Unauthenticated RCE Chain
Timeline of FortiSandbox Unauthenticated RCE Chain
- Defenders are advised to review FortiSandbox JRPC API access logs from this date onward as the earliest suspected probing window (per Fyntralink incident guidance).
- Fortinet publishes FG-IR-26-100 (CVE-2026-39808 OS command injection) and FG-IR-26-112 (CVE-2026-39813 JRPC API path-traversal auth bypass), releasing fixes in FortiSandbox 4.4.9 and 5.0.6.
- Help Net Security reports the April FortiSandbox disclosures (CVE-2026-39813, CVE-2026-39808), both rated critical.
- Greenbone publishes analysis and authenticated detection coverage for the April FortiSandbox RCE vulnerabilities (CVE-2026-39813, CVE-2026-39808) via its enterprise vulnerability tests.
- NVD last-modifies the CVE-2026-39808 record (CWE-78, CVSS 9.8), referencing FG-IR-26-100 and a public GitHub PoC.
- Fortinet publishes FG-IR-26-141 (CVE-2026-25089), a second-order OS command injection via the web UI 'start vnc' feature affecting FortiSandbox, Cloud, and PaaS; credited to Adham El Karn of Fortinet Product Security.
- Defused honeypot telemetry observes in-the-wild exploitation attempts across all three FortiSandbox CVEs within a 24-hour window, including an AI-authored ('vibecoded'), likely faulty exploit for CVE-2026-25089.
- runZero and Sangfor FarSight Labs publish asset-discovery and technical deep-dive guidance to help defenders locate exposed FortiSandbox appliances (e.g. runZero query os:="Fortinet FortiSandbox%") and dissect the CVE-2026-39813 path-traversal / is_valid_session() bypass mechanics.
- Help Net Security, BleepingComputer, and The Hacker News report active exploitation attempts; a public PoC for CVE-2026-39808 is available on GitHub. Fortinet has not formally confirmed compromise and the CVEs are not yet in the CISA KEV catalog.
Sources cited for FortiSandbox Unauthenticated RCE Chain
- Help Net Security — FortiSandbox vulnerabilities now being exploited (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089)
- Help Net Security — Fortinet fixes critical FortiSandbox vulnerabilities (CVE-2026-39813, CVE-2026-39808)
- The Hacker News — Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week
- BleepingComputer — Critical Fortinet FortiSandbox flaws now exploited in attacks
- Fortinet FortiGuard PSIRT — FG-IR-26-100 (CVE-2026-39808 OS command injection)
- Fortinet FortiGuard PSIRT — FG-IR-26-112 (CVE-2026-39813 JRPC API path-traversal auth bypass)
- Fortinet FortiGuard PSIRT — FG-IR-26-141 (CVE-2026-25089 second-order OS command injection via start vnc)
- NVD — CVE-2026-39808
- NVD — CVE-2026-39813
- Tenable — CVE-2026-25089
- runZero — Fortinet FortiSandbox vulnerabilities: Find impacted assets
- Greenbone — Fortinet RCE vulnerabilities 2026: Critical vulnerabilities in FortiSandbox
- Sangfor FarSight Labs — CVE-2026-39813: FortiSandbox Path Traversal Critical Vulnerability Guide
- imjdl blog — CVE-2026-39813 Deep Dive: Path Traversal Authentication Bypass in FortiSandbox JRPC API
- GitHub — samu-delucas/CVE-2026-39808 (public PoC, tracer-behavior jid injection)
Detection coverage for TL-2026-0823
As of 2026-06-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0823 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.