FortiSandbox
CVE-2021-26105: Stack-based buffer overflow in FortiSandbox
A stack-based buffer overflow vulnerability (CWE-121) in the profile parser of FortiSandbox version 3.2.2 and below, version 3.1.4 and below may allow an authenticated attacker to potentially execute unauthorized code or commands via specifically crafted HTTP requests.
Published
Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| FortiSandbox 3.2 | See the advisory |
| FortiSandbox 3.1 | See the advisory |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
A stack-based buffer overflow vulnerability (CWE-121) in the profile parser of FortiSandbox version 3.2.2 and below, version 3.1.4 and below may allow an authenticated attacker to potentially execute unauthorized code or commands via specifically crafted HTTP requests.
Sources
KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.