{
  "cve": "CVE-2026-39813",
  "enrichment": {
    "affected": [
      {
        "configurations": [
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "semver",
              "value": "[5.0.0,5.0.5]"
            }
          },
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "semver",
              "value": "[4.4.0,4.4.8]"
            }
          }
        ],
        "enrichment": {
          "confidence": 95.0,
          "confidence_source": "inferred",
          "scores": [
            {
              "score": 95.0,
              "source": "inferred"
            },
            {
              "score": 100.0,
              "source": "matching"
            }
          ]
        },
        "original": {
          "product": "FortiSandbox",
          "source": "cna",
          "vendor": "Fortinet"
        },
        "product": "fortisandbox",
        "vendor": "fortinet"
      },
      {
        "configurations": [
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "generic",
              "value": "24.1"
            }
          },
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "generic",
              "value": "23.4"
            }
          },
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "semver",
              "value": "[5.0.4,5.0.5]"
            }
          }
        ],
        "enrichment": {
          "confidence": 95.0,
          "confidence_source": "inferred",
          "scores": [
            {
              "score": 95.0,
              "source": "inferred"
            },
            {
              "score": 100.0,
              "source": "matching"
            }
          ]
        },
        "original": {
          "product": "FortiSandbox Cloud",
          "source": "cna",
          "vendor": "Fortinet"
        },
        "product": "fortisandboxcloud",
        "vendor": "fortinet"
      }
    ],
    "created": "2026-04-15T14:41:09.654680+00:00",
    "updated": "2026-09-24T23:30:17.462640+00:00",
    "vendors": [
      "fortinet",
      "fortinet$PRODUCT$fortisandbox",
      "fortinet$PRODUCT$fortisandboxcloud"
    ]
  },
  "epss": {
    "score": 0.0072
  },
  "mitre": {
    "cpes": [
      "cpe:2.3:a:fortinet:fortisandbox:4.4.0:*:*:*:*:*:*:*",
      "cpe:2.3:a:fortinet:fortisandbox:4.4.1:*:*:*:*:*:*:*",
      "cpe:2.3:a:fortinet:fortisandbox:4.4.2:*:*:*:*:*:*:*",
      "cpe:2.3:a:fortinet:fortisandbox:4.4.3:*:*:*:*:*:*:*",
      "cpe:2.3:a:fortinet:fortisandbox:4.4.4:*:*:*:*:*:*:*",
      "cpe:2.3:a:fortinet:fortisandbox:4.4.5:*:*:*:*:*:*:*",
      "cpe:2.3:a:fortinet:fortisandbox:4.4.6:*:*:*:*:*:*:*",
      "cpe:2.3:a:fortinet:fortisandbox:4.4.7:*:*:*:*:*:*:*",
      "cpe:2.3:a:fortinet:fortisandbox:4.4.8:*:*:*:*:*:*:*",
      "cpe:2.3:a:fortinet:fortisandbox:5.0.0:*:*:*:*:*:*:*",
      "cpe:2.3:a:fortinet:fortisandbox:5.0.1:*:*:*:*:*:*:*",
      "cpe:2.3:a:fortinet:fortisandbox:5.0.2:*:*:*:*:*:*:*",
      "cpe:2.3:a:fortinet:fortisandbox:5.0.3:*:*:*:*:*:*:*",
      "cpe:2.3:a:fortinet:fortisandbox:5.0.4:*:*:*:*:*:*:*",
      "cpe:2.3:a:fortinet:fortisandbox:5.0.5:*:*:*:*:*:*:*",
      "cpe:2.3:a:fortinet:fortisandboxcloud:23.4:*:*:*:*:*:*:*",
      "cpe:2.3:a:fortinet:fortisandboxcloud:24.1:*:*:*:*:*:*:*",
      "cpe:2.3:a:fortinet:fortisandboxcloud:5.0.4:*:*:*:*:*:*:*",
      "cpe:2.3:a:fortinet:fortisandboxcloud:5.0.5:*:*:*:*:*:*:*"
    ],
    "created": "2026-04-14T15:38:30.311000+00:00",
    "description": "A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially crafted HTTP requests.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 9.1,
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C"
      },
      "cvssV4_0": {}
    },
    "mitre_repo_path": "cves/2026/39xxx/CVE-2026-39813.json",
    "references": [
      "https://fortiguard.fortinet.com/psirt/FG-IR-26-112"
    ],
    "title": null,
    "updated": "2026-06-18T09:01:15.877000+00:00",
    "vendors": [
      "fortinet",
      "fortinet$PRODUCT$fortisandbox",
      "fortinet$PRODUCT$fortisandboxcloud"
    ],
    "weaknesses": [
      "CWE-24"
    ]
  },
  "nvd": {
    "cpes": [
      "cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*"
    ],
    "created": "2026-04-14T16:16:45.680000+00:00",
    "description": "A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially crafted HTTP requests.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 9.8,
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "cvssV4_0": {}
    },
    "nvd_repo_path": "2026/CVE-2026-39813.json",
    "references": [
      "https://fortiguard.fortinet.com/psirt/FG-IR-26-112"
    ],
    "title": null,
    "updated": "2026-06-18T13:25:36.770000+00:00",
    "vendors": [
      "fortinet",
      "fortinet$PRODUCT$fortisandbox"
    ],
    "weaknesses": [
      "CWE-24"
    ]
  },
  "opencve": {
    "changes": [
      {
        "created": "2026-04-14T16:00:00+00:00",
        "data": [
          {
            "details": {
              "new": "A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via <insert attack vector here>",
              "old": null
            },
            "type": "description"
          },
          {
            "details": [
              "fortinet",
              "fortinet$PRODUCT$fortisandbox",
              "fortinet$PRODUCT$fortisandboxcloud"
            ],
            "type": "first_time"
          },
          {
            "details": {
              "added": [
                "CWE-24"
              ],
              "removed": []
            },
            "type": "weaknesses"
          },
          {
            "details": {
              "added": [
                "cpe:2.3:a:fortinet:fortisandbox:4.4.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandbox:4.4.1:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandbox:4.4.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandbox:4.4.3:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandbox:4.4.4:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandbox:4.4.5:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandbox:4.4.6:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandbox:4.4.7:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandbox:4.4.8:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandbox:5.0.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandbox:5.0.1:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandbox:5.0.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandbox:5.0.3:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandbox:5.0.4:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandbox:5.0.5:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandboxcloud:23.4:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandboxcloud:24.1:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandboxcloud:5.0.4:*:*:*:*:*:*:*",
                "cpe:2.3:a:fortinet:fortisandboxcloud:5.0.5:*:*:*:*:*:*:*"
              ],
              "removed": []
            },
            "type": "cpes"
          },
          {
            "details": {
              "added": [
                "fortinet",
                "fortinet$PRODUCT$fortisandbox",
                "fortinet$PRODUCT$fortisandboxcloud"
              ],
              "removed": []
            },
            "type": "vendors"
          },
          {
            "details": {
              "added": [
                "https://fortiguard.fortinet.com/psirt/FG-IR-26-112"
              ],
              "removed": []
            },
            "type": "references"
          },
          {
            "details": {
              "added": {
                "cvssV3_1": {
                  "score": 9.1,
                  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "5eea3880-3339-4436-bb71-b5e2d2b352d9"
      },
      {
        "created": "2026-04-14T17:15:00+00:00",
        "data": [
          {
            "details": {
              "added": {
                "ssvc": {
                  "options": {
                    "Automatable": "yes",
                    "Exploitation": "none",
                    "Technical Impact": "total"
                  },
                  "version": "2.0.3"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "1423595c-ac7e-4b22-bcd8-54bcede94cca"
      },
      {
        "created": "2026-04-15T15:45:00+00:00",
        "data": [
          {
            "details": {
              "new": "Privilege Escalation via Path Traversal in FortiSandbox",
              "old": null
            },
            "type": "title"
          }
        ],
        "id": "6eb74d1e-ed35-4a9c-8bab-b9a315215eab"
      },
      {
        "created": "2026-04-20T19:15:00+00:00",
        "data": [
          {
            "details": {
              "added": [
                "cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*"
              ],
              "removed": []
            },
            "type": "cpes"
          }
        ],
        "id": "9066b150-bd57-43e9-88a5-d525ae55d813"
      },
      {
        "created": "2026-06-16T14:00:00+00:00",
        "data": [
          {
            "details": {
              "new": null,
              "old": "Privilege Escalation via Path Traversal in FortiSandbox"
            },
            "type": "title"
          }
        ],
        "id": "6497f2c2-7f30-4856-80ed-ade3d413b853"
      },
      {
        "created": "2026-06-17T11:30:00+00:00",
        "data": [
          {
            "details": {
              "new": "Path Traversal Exploitation Allowing Privilege Escalation in Fortinet FortiSandbox",
              "old": null
            },
            "type": "title"
          }
        ],
        "id": "7f096ee7-7064-456c-b689-6081ca10ed95"
      },
      {
        "created": "2026-06-18T16:45:00+00:00",
        "data": [
          {
            "details": {
              "new": "A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially crafted HTTP requests.",
              "old": "A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via <insert attack vector here>"
            },
            "type": "description"
          },
          {
            "details": {
              "new": null,
              "old": "Path Traversal Exploitation Allowing Privilege Escalation in Fortinet FortiSandbox"
            },
            "type": "title"
          }
        ],
        "id": "272825bb-0f83-4f73-995d-7ca3abd72f5a"
      },
      {
        "created": "2026-06-18T19:15:00+00:00",
        "data": [
          {
            "details": {
              "new": "FortiSandbox Path Traversal Enables Privilege Escalation via HTTP Requests",
              "old": null
            },
            "type": "title"
          }
        ],
        "id": "ea91f09d-d320-4c96-a3c5-c8ca57d81670"
      },
      {
        "created": "2026-06-23T17:00:00+00:00",
        "data": [
          {
            "details": {
              "new": null,
              "old": "FortiSandbox Path Traversal Enables Privilege Escalation via HTTP Requests"
            },
            "type": "title"
          }
        ],
        "id": "dce65084-bbcb-4ade-9a62-f5cbeb175bf5"
      },
      {
        "created": "2026-06-24T00:00:00+00:00",
        "data": [
          {
            "details": {
              "new": "Path Traversal Allowing Privilege Escalation via Specially Crafted HTTP Requests in FortiSandbox",
              "old": null
            },
            "type": "title"
          }
        ],
        "id": "f03fae65-9016-4687-961a-d941cade1b54"
      },
      {
        "created": "2026-06-24T03:45:00+00:00",
        "data": [
          {
            "details": {
              "new": null,
              "old": "Path Traversal Allowing Privilege Escalation via Specially Crafted HTTP Requests in FortiSandbox"
            },
            "type": "title"
          }
        ],
        "id": "90284966-f853-4f7f-9dba-167068e5c4f1"
      },
      {
        "created": "2026-06-24T06:00:00+00:00",
        "data": [
          {
            "details": {
              "new": "Directory Traversal Leading to Privilege Escalation in FortiSandbox",
              "old": null
            },
            "type": "title"
          }
        ],
        "id": "07096bb5-1a30-4bf1-94ac-ba85345bec7d"
      },
      {
        "created": "2026-06-24T10:00:00+00:00",
        "data": [
          {
            "details": {
              "new": null,
              "old": "Directory Traversal Leading to Privilege Escalation in FortiSandbox"
            },
            "type": "title"
          }
        ],
        "id": "6b429a55-867b-4b77-8cf8-a455a96c60f3"
      },
      {
        "created": "2026-07-30T00:45:00+00:00",
        "data": [
          {
            "details": {
              "new": "Directory Traversal Allowing Privilege Escalation in Fortinet FortiSandbox",
              "old": null
            },
            "type": "title"
          }
        ],
        "id": "5339926a-d66e-40cc-a76f-a8b4abcbf530"
      },
      {
        "created": "2026-08-04T09:00:00+00:00",
        "data": [
          {
            "details": {
              "new": null,
              "old": "Directory Traversal Allowing Privilege Escalation in Fortinet FortiSandbox"
            },
            "type": "title"
          }
        ],
        "id": "33971cb4-980e-4e4d-a849-fc1722aa977d"
      },
      {
        "created": "2026-09-10T15:15:00+00:00",
        "data": [
          {
            "details": {
              "new": "Privileged Escalation via Directory Traversal in Fortinet FortiSandbox",
              "old": null
            },
            "type": "title"
          }
        ],
        "id": "a025b900-4563-442c-bf74-d5bcfea9873f"
      },
      {
        "created": "2026-09-24T23:45:00+00:00",
        "data": [
          {
            "details": {
              "new": null,
              "old": "Privileged Escalation via Directory Traversal in Fortinet FortiSandbox"
            },
            "type": "title"
          }
        ],
        "id": "1705ff62-724a-4fa4-81ea-c0782a49c86b"
      }
    ],
    "cpes": {
      "data": [
        "cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:fortinet:fortisandbox:4.4.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:fortinet:fortisandbox:4.4.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:fortinet:fortisandbox:4.4.2:*:*:*:*:*:*:*",
        "cpe:2.3:a:fortinet:fortisandbox:4.4.3:*:*:*:*:*:*:*",
        "cpe:2.3:a:fortinet:fortisandbox:4.4.4:*:*:*:*:*:*:*",
        "cpe:2.3:a:fortinet:fortisandbox:4.4.5:*:*:*:*:*:*:*",
        "cpe:2.3:a:fortinet:fortisandbox:4.4.6:*:*:*:*:*:*:*",
        "cpe:2.3:a:fortinet:fortisandbox:4.4.7:*:*:*:*:*:*:*",
        "cpe:2.3:a:fortinet:fortisandbox:4.4.8:*:*:*:*:*:*:*",
        "cpe:2.3:a:fortinet:fortisandbox:5.0.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:fortinet:fortisandbox:5.0.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:fortinet:fortisandbox:5.0.2:*:*:*:*:*:*:*",
        "cpe:2.3:a:fortinet:fortisandbox:5.0.3:*:*:*:*:*:*:*",
        "cpe:2.3:a:fortinet:fortisandbox:5.0.4:*:*:*:*:*:*:*",
        "cpe:2.3:a:fortinet:fortisandbox:5.0.5:*:*:*:*:*:*:*",
        "cpe:2.3:a:fortinet:fortisandboxcloud:23.4:*:*:*:*:*:*:*",
        "cpe:2.3:a:fortinet:fortisandboxcloud:24.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:fortinet:fortisandboxcloud:5.0.4:*:*:*:*:*:*:*",
        "cpe:2.3:a:fortinet:fortisandboxcloud:5.0.5:*:*:*:*:*:*:*"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    },
    "created": {
      "data": "2026-04-14T15:38:30.311000+00:00",
      "provider": "mitre"
    },
    "description": {
      "data": "A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially crafted HTTP requests.",
      "provider": "mitre"
    },
    "metrics": {
      "cvssV2_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_1": {
        "data": {
          "score": 9.1,
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C"
        },
        "provider": "mitre"
      },
      "cvssV4_0": {
        "data": {},
        "provider": null
      },
      "epss": {
        "data": {
          "score": 0.0072
        },
        "provider": "first"
      },
      "kev": {
        "data": {},
        "provider": null
      },
      "ssvc": {
        "data": {
          "options": {
            "Automatable": "yes",
            "Exploitation": "none",
            "Technical Impact": "total"
          },
          "version": "2.0.3"
        },
        "provider": "vulnrichment"
      },
      "threat_severity": {
        "data": null,
        "provider": null
      }
    },
    "references": {
      "data": [
        "https://fortiguard.fortinet.com/psirt/FG-IR-26-112"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    },
    "title": {
      "data": null,
      "provider": null
    },
    "updated": {
      "data": "2026-09-24T23:30:17.462640+00:00",
      "provider": "enrichment"
    },
    "vendors": {
      "data": [
        "fortinet",
        "fortinet$PRODUCT$fortisandbox",
        "fortinet$PRODUCT$fortisandboxcloud"
      ],
      "providers": [
        "mitre",
        "nvd",
        "enrichment"
      ]
    },
    "weaknesses": {
      "data": [
        "CWE-24"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    }
  },
  "vulnrichment": {
    "cpes": [],
    "created": "2026-04-14T15:38:30.311000+00:00",
    "description": "A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially crafted HTTP requests.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {},
      "cvssV4_0": {},
      "kev": {},
      "ssvc": {
        "options": {
          "Automatable": "yes",
          "Exploitation": "none",
          "Technical Impact": "total"
        },
        "version": "2.0.3"
      }
    },
    "references": [],
    "title": null,
    "updated": "2026-04-14T16:36:55.508000+00:00",
    "vendors": [],
    "vulnrichment_repo_path": "2026/39xxx/CVE-2026-39813.json",
    "weaknesses": []
  }
}