ZDI-26-645: Fortinet FortiSandbox write_remote_backup_to_crontab Command Injection RCE Vulnerability

Executive Summary

A command injection flaw in Fortinet FortiSandbox’s write_remote_backup_to_crontab function allows authenticated attackers to inject arbitrary cron commands, leading to remote code execution. The vulnerability, identified as CVE-2026-84387, carries a CVSS score of 7.2 and was disclosed by Zero Day Initiative.


Intelligence Metadata - Source Publisher: Zero Day Initiative - Published Date: 2026-09-09T05:00:00+00:00 - Category: cves

Original Description: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fortinet FortiSandbox. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-84387.

"A thing long expected takes the form of the unexpected when at last it comes."

— Mark Twain
Source: Zero Day Initiative