{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2026-25089",
  "revision": 1,
  "title": "Fortinet FortiSandbox — unauthenticated OS command injection RCE",
  "summary": "Fortinet FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS fail to sanitize input used in operating system commands. An attacker with no account can send crafted web (HTTP) requests and run arbitrary commands on the appliance. Actively exploited in the wild.",
  "source_type": "cve",
  "severity": "critical",
  "cvss": {
    "score": 9.8,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.76112,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2026-07-16",
    "prerequisites": "Network access to the FortiSandbox HTTP interface; no account or user interaction needed."
  },
  "mitre_attack": [
    "T1190",
    "T1059"
  ],
  "kill_chain": "initial_access",
  "recommended_action": "Apply the fix from Fortinet advisory FG-IR-26-141 now; until then restrict access to the FortiSandbox web interface and review it for signs of compromise.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-25089",
      "retrieved_at": "2026-09-22T06:10:25.213Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-22T06:10:25.213Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2026-25089",
      "retrieved_at": "2026-09-22T06:10:25.213Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-25089",
      "retrieved_at": "2026-09-22T06:10:25.213Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25089",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://fortiguard.fortinet.com/psirt/FG-IR-26-141"
    }
  ],
  "published_at": "2026-06-09T16:16:39.943Z",
  "issued_at": "2026-09-22T06:10:25.213Z",
  "tags": [
    "fortinet",
    "fortisandbox",
    "os-command-injection",
    "rce",
    "kev"
  ]
}
