FortinetCVE-2026-59835
Fortinet FortiSandbox: unauthenticated attacker could access the VNC server of...
High8.6CVE-2026-59835 · Published Jul 14, 2026 · updated Jul 15, 2026
A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| FortiSandbox Product | >= 5.0.0, <= 5.0.2 | No fix yet |
| >= 4.4.3, <= 4.4.8 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-668
More Fortinet advisories
All Fortinet| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 14 | Fortinet FortiOS: path traversal | Medium5.5 | No fix yet |
| Jul 14 | Fortinet FortiOS: information disclosure | Medium4.3 | No fix yet |
| Jul 14 | Fortinet FortiSIEMWindowsAgent: privilege escalation | High7.5 | No fix yet |
| Jul 14 | Fortinet FortiClientEMS: improper certificate validation | High7.5 | No fix yet |
| Jul 14 | Fortinet FortiOS: stack buffer overflow | Medium6.6 | No fix yet |
| Jul 14 | Fortinet FortiOS: cross-site scripting | Medium6.1 | No fix yet |