FortiSandbox Unauthenticated Control of NAT Rules Leading to Exposure of Sensitive Information
Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 8.9, CVEs: CVE-2026-26084, Summary: An improper access control vulnerability [CWE-284] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to access sensitive information via crafted HTTP requests.
CVSS 8.9 CVE-2026-26084 Fortinet FI