File scan result bypass

Summary

An Improper Isolation or Compartmentalization vulnerability [CWE-653] in FortiSandbox may allow an unauthenticated attacker to evade the sandboxing scan via a crafted file.

Version Affected Solution
FortiSandbox 5.0 5.0.0 through 5.0.1 Upgrade to 5.0.2 or above
FortiSandbox 4.4 4.4.0 through 4.4.7 Upgrade to 4.4.8 or above
FortiSandbox 4.2 4.2 all versions Migrate to a fixed release
FortiSandbox 4.0 4.0 all versions Migrate to a fixed release

Workaround:
FortiSandbox 4.4: Upgrade the Tracer Engine to version 04004.00477 or above.

Acknowledgement

Fortinet is pleased to thank Greg Roll for reporting this vulnerability under responsible disclosure.

Timeline

2025-11-18: Initial publication