Skip to content
Auto-CTI
Back to today
NEW CRITICAL B2

ZDI-26-645: Fortinet FortiSandbox write_remote_backup_to_crontab cronValue Command Injection Remote Code Execution Vulnerability

B ZDI: Published Advisories · · CVE-2026-84387

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key metrics

CVSS
7.2
EPSS
1%

Key insight

Authenticated remote code execution in Fortinet FortiSandbox via command injection allows attackers to compromise systems where the product is deployed.

Description

CVE-2026-84387 affects Fortinet FortiSandbox and allows authenticated remote attackers to execute arbitrary code on affected installations. The vulnerability stems from insufficient validation of cronValue parameters in the write_remote_backup_to_crontab function, leading to command injection. The CVSS score is 7.2 (High), indicating significant severity. Authentication is required, limiting risk to internal or authorized users.

Risk score

Models disagree 98
cvss base
72.00
kev bonus
0.00
epss bonus
0.00
poc bonus
15.00
raw before weight
87.00
industry weight
1.21
freshness factor
1.00
exploitability factor
1.00
days old
0.00
vendor mismatch penalty
0.00
vote penalty
-2.00

Path: operational

Consensus check

Models disagree: Models disagree on severity

Vote penalty:
−2.0
Total penalty:
−2.0
ESC