CVE-2026-59835: Unauthenticated VNC access exposed on all interfaces
A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests.
Other sources
An Exposure of Resource to Wrong Sphere vulnerability [CWE-668] in FortiSandbox may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests.
— FortiGuard
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Fortinet FortiSandboxto a version that resolves this vulnerability.Fixed in 4.4.9 - Upgrade
Upgrade
Fortinet FortiSandboxto a version that resolves this vulnerability.Fixed in 5.0.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59835?
The severity of CVE-2026-59835 is high with a CVSS score of 8.6.
How do I fix CVE-2026-59835?
To fix CVE-2026-59835, update Fortinet FortiSandbox to version 5.0.3 or later.
What systems are affected by CVE-2026-59835?
CVE-2026-59835 affects Fortinet FortiSandbox versions 5.0.0 through 5.0.2 and 4.4.3 through 4.4.8.
What type of vulnerability is CVE-2026-59835?
CVE-2026-59835 is classified as an Exposure of Resource to Wrong Sphere vulnerability.
What impact does CVE-2026-59835 have on security?
CVE-2026-59835 allows unauthenticated attackers to access the VNC server of virtual machines, potentially compromising sensitive information.