CVE-2026-104286 Fortinet FortiMail: Path Traversal
9.8 KEV Laut CISA aktiv ausgenutzt
Analyse auf rafaelpfister.ch
Beschreibung des Herstellers (englisch)
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. Stammdaten
- Hersteller
- Fortinet
- Betroffene Produkte
- FortiMail
- CVSS 3.1
- 9.8 (CRITICAL)
- Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C- Schwachstellentyp
- CWE-22: Path Traversal
- Veröffentlicht
- 1. Oktober 2026
- Im KEV-Katalog seit
- 1. Oktober 2026
- Frist US-Bundesbehörden
- 4. Oktober 2026