πŸ”΄ CVE-2026-104286

CVE-2026-104286 is a critical unauthenticated path traversal vulnerability (CWE-22) in Fortinet FortiMail affecting versions 7.0.x through 8.0.x. An unauthenticated remote attacker can write arbitrary files to the underlying system via crafted HTTP/HTTPS requests, which can directly lead to remote code execution and full system compromise. FortiMail is an email security gateway that is routinely deployed as an internet-facing service, making this vulnerability directly exploitable via T1190.

← Back to Overview
HIGH_RISK
Risk Level
9.8
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 β€” Exploit Public-Facing Application
ATT&CK Technique
HIGH
Deployment Risk
No
Ransomware

πŸ“‹ Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2026-10-01

Added to CISA KEV: 2026-10-01 0 DAY BETWEEN CVE AND KEV

🎯 Recommendations:

πŸ” Web Intelligence (Kagi Β· 2026-10-01)

Summary

CVE-2026-104286 is a path traversal vulnerability affecting multiple versions of Fortinet FortiMail. This vulnerability stems from an improper limitation of pathnames to a restricted directory, which allows an unauthenticated, remote attacker to write arbitrary files onto the underlying system through crafted HTTP or HTTPS requests. Because this flaw enables unauthenticated remote code execution or system configuration tampering, it poses a severe security risk to affected appliances.

Exploitation

  • Active Exploitation: There are currently no reports of widespread active exploitation of this CVE in the wild.
  • Threat Actors/Campaigns: No specific threat actors or ransomware campaigns have been publicly linked to this vulnerability.
  • Proof-of-Concept: No public proof-of-concept (PoC) exploit code or automated attack tools are currently widely available.
  • Attack Prerequisites:
- The attack is network-based and can be performed remotely. - No authentication is required to initiate the attack. - No user interaction is required from a legitimate user.

Affected Products & Patches

  • Affected Product Versions:
- FortiMail 8.0.0 through 8.0.1 - FortiMail 7.6.0 through 7.6.6 - FortiMail 7.4.0 through 7.4.8 - FortiMail 7.2.0 through 7.2.9
  • Patches/Hotfixes: Users should refer to the official [Fortinet PSIRT Advisories](https://www.fortiguard.com/psirt) page for the latest firmware versions that address this vulnerability and upgrade immediately.
  • Mitigations/Workarounds: If an immediate upgrade is not possible, organizations should restrict management interface access to trusted networks only and monitor traffic for suspicious HTTP/HTTPS requests containing directory traversal sequences.

Impact

  • Access/Capability: Successful exploitation grants the attacker the ability to write arbitrary files to the FortiMail system, which can lead to full system compromise, the installation of backdoors, or the modification of critical system files.
  • Business Risk: For internet-facing deployments, this vulnerability is critical. An attacker could completely take over the email security gateway, leading to the interception of sensitive corporate communications, disruption of email services, or use of the compromised appliance as a beachhead to attack internal network resources. [1]

Sources

  1. CVE-2026-104286 - Vulnerability Details - OpenCVE

    An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the…