{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2026-39808",
  "revision": 1,
  "title": "Fortinet FortiSandbox — unauthenticated OS command injection RCE",
  "summary": "Fortinet FortiSandbox 4.4.0 through 4.4.8 passes unsanitized input into operating system commands. An unauthenticated attacker who can reach the device with crafted web (HTTP) requests can run arbitrary commands and take over the appliance. Exploited in the wild.",
  "source_type": "cve",
  "severity": "critical",
  "cvss": {
    "score": 9.8,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.92819,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": true,
    "attack_complexity": "low",
    "kev_added": "2026-07-16",
    "prerequisites": "Network access to the FortiSandbox HTTP interface; no credentials or user interaction required."
  },
  "mitre_attack": [
    "T1190",
    "T1059"
  ],
  "kill_chain": "initial_access",
  "recommended_action": "Apply the fix in Fortinet advisory FG-IR-26-100 now; block internet access to FortiSandbox 4.4.x until patched and hunt for unexpected processes and HTTP requests.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-39808",
      "retrieved_at": "2026-09-22T06:10:25.213Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-22T06:10:25.213Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2026-39808",
      "retrieved_at": "2026-09-22T06:10:25.213Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-39808",
      "retrieved_at": "2026-09-22T06:10:25.213Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39808",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://fortiguard.fortinet.com/psirt/FG-IR-26-100"
    },
    {
      "type": "exploit",
      "url": "https://github.com/samu-delucas/CVE-2026-39808"
    }
  ],
  "published_at": "2026-04-14T16:16:44.860Z",
  "issued_at": "2026-09-22T06:10:25.213Z",
  "tags": [
    "fortinet",
    "fortisandbox",
    "os-command-injection",
    "rce",
    "kev"
  ]
}
