內容說明
Fortinet 旗下 FortiSandbox、FortiSandbox Cloud 及 FortiSandbox PaaS 的網頁介面存在缺少授權漏洞 (CVE-2026-26089,CVSS:9.8)。未經身分驗證的遠端攻擊者可能透過特製 HTTP 請求, 執行未經授權的程式碼或命令。
影響平台
- FortiSandbox 5.0.0 至 5.0.5 版本
- FortiSandbox 4.4.0 至 4.4.8 版本
- FortiSandbox Cloud 5.0.4 至 5.0.5 版本
- FortiSandbox PaaS 5.0.4 至 5.0.5 版本
建議措施
請儘速更新至以下版本或後續版本,以降低資安風險:
- FortiSandbox 5.0.6(含)以上版本
- FortiSandbox 4.4.9(含)以上版本
- FortiSandbox Cloud 5.0.6(含)以上版本
- FortiSandbox PaaS 5.0.6(含)以上版本

