# FortiSandbox Unauthenticated RCE Chain: JRPC API Path-Traversal Auth Bypass and OS Command Injection (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089)

> Three critical FortiSandbox flaws enable unauthenticated remote code execution on a malware-analysis security appliance: a JRPC API path-traversal authentication bypass (CVE-2026-39813), an OS command injection on the tracer-behavior API endpoint (CVE-2026-39808), and a second-order OS command injection in the web UI 'start vnc' feature affecting FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS (CVE-2026-25089). Fortinet patched the first two on 14 Apr 2026 (FG-IR-26-100, FG-IR-26-112) and the third on 9 Jun 2026 (FG-IR-26-141); Defused observed in-the-wild exploitation attempts across all three within a 24-hour window on 15-16 Jun 2026, including an AI-generated ('vibecoded') and likely faulty exploit for CVE-2026-25089.

- **Published:** 2026-06-16T00:00:00Z
- **Last reviewed:** 2026-06-16T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0823
- **ID:** TL-2026-0823
- **Severity:** CRITICAL (CVSS 9.8)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 15 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-39813, CVE-2026-39808, CVE-2026-25089

## Description

FortiSandbox is Fortinet's network sandbox / detonation appliance used by SOCs to detonate suspicious files and URLs and render malware verdicts. Three vulnerabilities disclosed in 2026 combine to give a remote, unauthenticated attacker root-level code execution on the appliance itself — turning a defensive control into an attacker foothold and giving the adversary the ability to read, suppress, or poison malware verdicts.

CVE-2026-39813 (FG-IR-26-112, CWE-24/CWE-22 path traversal, CVSS 9.1 per Fortinet / 9.8 per NVD) is an authentication bypass in the JRPC API. The /jsonrpc/ endpoint is whitelisted in the Django middleware, so it skips the Layer-1 web authentication; Layer-2 session validation in is_valid_session() passes a user-controlled 'session' value straight into os.path.join(DIRRPCSESS, session_id) with no sanitization. Because Python's os.path.join() preserves leading '..' components, a payload of "session": "../../tmp/" resolves /usr/rpcsess/../../tmp/ to /tmp/ — a directory that always exists and whose modification time is continuously refreshed by system processes, satisfying the only two checks the validator performs (path exists, mtime within 3600s). The attacker thereby impersonates a privileged JRPC session without credentials and can invoke read methods such as sys/status (system information, 26 fields), sys/system_resource, config/scan/options, and backup/config (a ~32KB encrypted system backup).

CVE-2026-39808 (FG-IR-26-100, CWE-78 OS command injection, CVSS 9.1 per Fortinet / 9.8 per NVD) lives in an API endpoint that improperly neutralizes special elements. A public PoC targets the GET endpoint /fortisandbox/job-detail/tracer-behavior, injecting shell commands through the unsanitized 'jid' parameter using pipe characters — e.g. jid=|(id > /web/ng/out.txt)| — with output redirected into the web root (/web/ng/) for later HTTP retrieval. Commands execute with the privileges of the sandbox service (reported as root). Chained with CVE-2026-39813, an attacker can pivot from authentication bypass to full unauthenticated RCE.

CVE-2026-25089 (FG-IR-26-141, CWE-78, CVSS 9.1) is a second-order OS command injection via JSON input on the 'start vnc' feature in the web UI, allowing an unauthenticated attacker to execute unauthorized commands via crafted HTTP requests. It affects FortiSandbox 4.2 (all), 4.4.0-4.4.8, 5.0.0-5.0.5, and FortiSandbox Cloud/PaaS 5.0.4-5.0.5; it was disclosed on 9 Jun 2026, roughly a week before the active-exploitation reporting, and was credited to Adham El Karn of the Fortinet Product Security team.

Fortinet released fixes in FortiSandbox 4.4.9 and 5.0.6. As of mid-June 2026 the CVEs were not yet listed in the CISA KEV catalog and Fortinet had not formally confirmed in-the-wild compromise, but Defused/Defused-Cyber honeypot telemetry reported active exploitation attempts of all three within a single 24-hour window, with at least one CVE-2026-25089 exploit showing signs of AI ('vibecoded') authorship and being likely faulty. FortiSandbox vulnerabilities have not historically been a common attacker target, so the surge represents a notable shift. Because the appliance is a security control, post-patch hunting must include reviewing JRPC API access logs and the web UI for /jsonrpc/ requests containing '../', unusual command patterns on the tracer-behavior endpoint, suspicious files in /web/ng/, and re-validation of recent sandbox file verdicts.

## MITRE ATT&CK

- T1595 Active Scanning
- T1587 Develop Capabilities
- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1505 Server Software Component
- T1068 Exploitation for Privilege Escalation
- T1211 Exploitation for Stealth
- T1685 Disable or Modify Tools
- T1212 Exploitation for Credential Access
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1007 System Service Discovery
- T1005 Data from Local System
- T1567 Exfiltration Over Web Service

## Sources

- [Help Net Security — FortiSandbox vulnerabilities now being exploited (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089)](https://www.helpnetsecurity.com/2026/06/16/fortisandbox-vulnerabilities-cve-2026-39813-cve-2026-39808-cve-2026-25089/)
- [Help Net Security — Fortinet fixes critical FortiSandbox vulnerabilities (CVE-2026-39813, CVE-2026-39808)](https://www.helpnetsecurity.com/2026/04/16/fortinet-fortisandbox-vulnerabilities-cve-2026-39813-cve-2026-39808/)
- [The Hacker News — Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week](https://thehackernews.com/2026/06/attackers-exploit-three-fortinet.html)
- [BleepingComputer — Critical Fortinet FortiSandbox flaws now exploited in attacks](https://www.bleepingcomputer.com/news/security/critical-fortinet-fortisandbox-flaws-now-exploited-in-attacks/)
- [Fortinet FortiGuard PSIRT — FG-IR-26-100 (CVE-2026-39808 OS command injection)](https://fortiguard.fortinet.com/psirt/FG-IR-26-100)
- [Fortinet FortiGuard PSIRT — FG-IR-26-112 (CVE-2026-39813 JRPC API path-traversal auth bypass)](https://fortiguard.fortinet.com/psirt/FG-IR-26-112)
- [Fortinet FortiGuard PSIRT — FG-IR-26-141 (CVE-2026-25089 second-order OS command injection via start vnc)](https://fortiguard.fortinet.com/psirt/FG-IR-26-141)
- [NVD — CVE-2026-39808](https://nvd.nist.gov/vuln/detail/CVE-2026-39808)
- [NVD — CVE-2026-39813](https://nvd.nist.gov/vuln/detail/CVE-2026-39813)
- [Tenable — CVE-2026-25089](https://www.tenable.com/cve/CVE-2026-25089)
- [runZero — Fortinet FortiSandbox vulnerabilities: Find impacted assets](https://www.runzero.com/blog/fortinet-fortisandbox/)
- [Greenbone — Fortinet RCE vulnerabilities 2026: Critical vulnerabilities in FortiSandbox](https://www.greenbone.net/en/blog/fortinet-rce-vulnerabilities-2026-critical-vulnerabilities-in-fortisandbox/)
- [Sangfor FarSight Labs — CVE-2026-39813: FortiSandbox Path Traversal Critical Vulnerability Guide](https://www.sangfor.com/farsight-labs-threat-intelligence/cybersecurity/fortisandbox-path-traversal-cve-2026-39813)
- [imjdl blog — CVE-2026-39813 Deep Dive: Path Traversal Authentication Bypass in FortiSandbox JRPC API](https://rustlang.rs/posts/blog_cve_2026_39813_en/)
- [GitHub — samu-delucas/CVE-2026-39808 (public PoC, tracer-behavior jid injection)](https://github.com/samu-delucas/CVE-2026-39808)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0823
