The SentinelOne Annual Threat Report - A Defenders Guide from the FrontlinesThe SentinelOne Annual Threat ReportGet the Report
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-25691

CVE-2026-25691: FortiSandbox Path Traversal Vulnerability

CVE-2026-25691 is a path traversal flaw in Fortinet FortiSandbox that enables privileged attackers to delete arbitrary directories. This article covers technical details, affected versions, impact, and mitigation.

Published: April 17, 2026

CVE-2026-25691 Overview

A path traversal vulnerability (CWE-22) has been identified in Fortinet FortiSandbox products that allows a privileged attacker with super-admin profile and CLI access to delete arbitrary directories via specially crafted HTTP requests. This vulnerability affects multiple versions of FortiSandbox including on-premises, cloud, and PaaS deployments.

Critical Impact

Privileged attackers can exploit this path traversal flaw to delete arbitrary directories on affected FortiSandbox systems, potentially causing significant data loss, service disruption, or compromising the integrity of sandboxed malware analysis operations.

Affected Products

  • Fortinet FortiSandbox 5.0.0 through 5.0.5
  • Fortinet FortiSandbox 4.4.0 through 4.4.8
  • Fortinet FortiSandbox 4.2 all versions
  • Fortinet FortiSandbox Cloud 5.0.4
  • Fortinet FortiSandbox PaaS 5.0.4

Discovery Timeline

  • 2026-04-14 - CVE-2026-25691 published to NVD
  • 2026-04-14 - Last updated in NVD database

Technical Details for CVE-2026-25691

Vulnerability Analysis

This vulnerability is classified as an Improper Limitation of a Pathname to a Restricted Directory, commonly known as path traversal or directory traversal (CWE-22). The flaw exists in how FortiSandbox processes HTTP requests containing file system paths, allowing attackers to escape intended directory restrictions.

The vulnerability requires elevated privileges to exploit, specifically a super-admin profile with CLI access. While this requirement limits the potential attack surface, organizations must consider insider threats, compromised administrator credentials, or lateral movement scenarios where an attacker has already obtained privileged access to the FortiSandbox management interface.

The impact of successful exploitation includes the ability to delete arbitrary directories on the affected system. This could lead to denial of service conditions, loss of critical security logs and analysis data, disruption of malware sandboxing operations, or manipulation of the FortiSandbox environment to evade detection.

Root Cause

The root cause of this vulnerability lies in insufficient input validation and sanitization of pathname parameters in HTTP request handling. The application fails to properly restrict directory traversal sequences (such as ../ or encoded variants) in user-supplied input, allowing attackers to reference directories outside the intended scope.

When processing certain HTTP requests, the FortiSandbox CLI interface does not adequately validate that the target path remains within authorized directory boundaries. This allows an authenticated super-admin user to craft malicious requests that traverse the directory structure and target arbitrary directories for deletion.

Attack Vector

The attack is conducted over the network through crafted HTTP requests targeting the FortiSandbox management interface. An attacker must first authenticate with super-admin credentials and have CLI access to the system.

The exploitation process involves:

  1. Authenticating to the FortiSandbox management interface with a super-admin account
  2. Accessing the CLI functionality through the web interface
  3. Crafting HTTP requests containing path traversal sequences designed to escape directory restrictions
  4. Targeting specific directories for deletion through the manipulated path parameters

The vulnerability does not require user interaction and can be exploited directly by an authenticated privileged user. For technical details regarding the specific vulnerable endpoints and exploitation methods, refer to the Fortinet Security Advisory FG-IR-26-115.

Detection Methods for CVE-2026-25691

Indicators of Compromise

  • Unexpected directory deletions on FortiSandbox systems, particularly system directories or analysis data folders
  • Unusual HTTP request patterns in web server logs containing path traversal sequences (../, ..%2f, %2e%2e/)
  • Super-admin account activity from unusual IP addresses or at unusual times
  • Service disruptions or missing analysis data in FortiSandbox operations

Detection Strategies

  • Monitor FortiSandbox web server access logs for HTTP requests containing directory traversal patterns in URL parameters or request bodies
  • Implement file integrity monitoring on critical FortiSandbox directories to detect unauthorized deletions
  • Enable comprehensive audit logging for all super-admin activities and CLI command execution
  • Deploy network traffic analysis to identify anomalous HTTP request patterns targeting FortiSandbox management interfaces

Monitoring Recommendations

  • Configure alerting for any deletion operations affecting system-critical directories on FortiSandbox appliances
  • Establish baselines for normal super-admin activity and alert on deviations
  • Monitor authentication logs for super-admin account access patterns and investigate anomalies
  • Implement SIEM correlation rules to detect potential path traversal exploitation attempts

How to Mitigate CVE-2026-25691

Immediate Actions Required

  • Review and restrict super-admin account access to only essential personnel
  • Audit all privileged account activity on affected FortiSandbox systems for suspicious behavior
  • Implement network segmentation to limit access to FortiSandbox management interfaces
  • Apply vendor patches as soon as they become available from Fortinet

Patch Information

Fortinet has published security advisory FG-IR-26-115 addressing this vulnerability. Organizations should review the advisory for specific patch versions and upgrade paths for their affected FortiSandbox deployments.

Affected organizations should upgrade to patched versions of FortiSandbox as specified in the Fortinet security advisory. Contact Fortinet support or refer to FortiGuard for the latest firmware versions that address this vulnerability.

Workarounds

  • Restrict network access to FortiSandbox management interfaces using firewall rules and ACLs to limit exposure
  • Implement multi-factor authentication for all super-admin accounts to reduce the risk of credential compromise
  • Conduct regular audits of super-admin account membership and remove unnecessary privileged access
  • Consider deploying a web application firewall (WAF) in front of FortiSandbox management interfaces to filter path traversal attempts
bash
# Example: Restrict management interface access via firewall rules
# Limit FortiSandbox management access to trusted administrator networks only
# Consult your FortiSandbox documentation for specific configuration syntax

# Review and audit super-admin accounts
# Access FortiSandbox CLI and review privileged users
# diagnose sys admin list

# Enable comprehensive audit logging
# config system global
#   set admin-audit-log enable
# end

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypePath Traversal

  • Vendor/TechFortisandbox

  • SeverityMEDIUM

  • CVSS Score6.7

  • EPSS Probability0.04%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityHigh
  • CWE References
  • CWE-22
  • Technical References
  • Fortinet Security Advisory FG-IR-26-115
  • Related CVEs
  • CVE-2026-39813: FortiSandbox Path Traversal Vulnerability

  • CVE-2026-39812: Fortinet FortiSandbox XSS Vulnerability

  • CVE-2026-27316: FortiSandbox Credential Exposure Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the World’s Most Advanced Cybersecurity Platform

See how our intelligent, autonomous cybersecurity platform can protect your organization now and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English