CVE-2026-104286 is a critical unauthenticated path traversal vulnerability (CWE-22) in Fortinet FortiMail affecting versions 7.0.x through 8.0.x. An unauthenticated remote attacker can write arbitrary files to the underlying system via crafted HTTP/HTTPS requests, which can directly lead to remote code execution and full system compromise. FortiMail is an email security gateway that is routinely deployed as an internet-facing service, making this vulnerability directly exploitable via T1190.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2026-10-01
Added to CISA KEV: 2026-10-01 0 DAY BETWEEN CVE AND KEV
CVE-2026-104286 is a path traversal vulnerability affecting multiple versions of Fortinet FortiMail. This vulnerability stems from an improper limitation of pathnames to a restricted directory, which allows an unauthenticated, remote attacker to write arbitrary files onto the underlying system through crafted HTTP or HTTPS requests. Because this flaw enables unauthenticated remote code execution or system configuration tampering, it poses a severe security risk to affected appliances.
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on theβ¦