CVE-2026-104286 Fortinet FortiMail: Path Traversal
9.8 KEV Actively exploited according to CISA
Analysis on rafaelpfister.ch
Vendor description
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. Reference data
- Vendor
- Fortinet
- Affected products
- FortiMail
- CVSS 3.1
- 9.8 (CRITICAL)
- Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C- Weakness type
- CWE-22: Path Traversal
- Published
- October 1, 2026
- In KEV catalog since
- October 1, 2026
- US federal deadline
- October 4, 2026