← Vulnerability feed

Vulnerability record · CVE-2024-27779 · published 18 July 2025

CVE-2024-27779: Fortinet fortiisolator insufficient session expiration vulnerability

Fortinet · Fortiisolator

An insufficient session expiration vulnerability [CWE-613] in FortiSandbox FortiSandbox version 4.4.4 and below, version 4.2.6 and below, 4.0 all versions, 3.2 all versions and FortiIsolator version 2.4 and below, 2.3 all versions, 2.2 all versions, 2.1 all versions, 2.0 all versions, 1.2 all versions may allow a remote attacker in possession of an admin session cookie to keep using that admin's session even after the admin user was deleted.

6.7 CVSS 3.1 Medium EPSS 0.47% · top 61.5% CWE-613 · Insufficient session expiration
6.7CVSS 3.1 base score
0.47%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

An insufficient session expiration vulnerability [CWE-613] in FortiSandbox FortiSandbox version 4.4.4 and below, version 4.2.6 and below, 4.0 all versions, 3.2 all versions and FortiIsolator version 2.4 and below, 2.3 all versions, 2.2 all versions, 2.1 all versions, 2.0 all versions, 1.2 all versions may allow a remote attacker in possession of an admin session cookie to keep using that admin's session even after the admin user was deleted.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-27779 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-25089Fortinet FortiSandbox unauthenticated OS command injectionFortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS fail to neutralize special elements in HTTP request handling, allowing OS command injection (C…KEVEPSS 76%analysed9.8CVE-2026-39808Fortinet FortiSandbox OS command injectionFortiSandbox 4.4.0 through 4.4.8 fails to neutralize special elements used in OS commands, allowing command injection. The flaw is remotely reachable…KEVEPSS 47%analysed9.8CVE-2026-26083Fortinet fortisandbox missing authorization vulnerabilityA missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 throug…EPSS 0.50%9.8CVE-2026-39813Fortinet fortisandbox vulnerabilityA path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to esc…EPSS 0.72%9.8CVE-2020-6649Fortinet fortiisolator insufficient session expiration vulnerabilityAn insufficient session expiration vulnerability in FortiNet's FortiIsolator version 2.0.1 and below may allow an attacker to reuse the unexpired adm…EPSS 1.5%9.6CVE-2025-52436Fortinet fortisandbox cross-site scripting vulnerabilityAn Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox…EPSS 6.5%9.1CVE-2024-33507Fortinet fortiisolator insufficient session expiration vulnerabilityAn insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in FortiIsolator 2.4.0 through 2.4.…EPSS 0.39%9.0CVE-2024-27781Fortinet fortisandbox cross-site scripting vulnerabilityAn improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, F…EPSS 28%

Source: NIST National Vulnerability Database (record CVE-2024-27779), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.