CVE-2026-104286 Fortinet FortiMail: Path Traversal
9.8 KEV Explotada activamente según la CISA
Análisis en rafaelpfister.ch
Descripción del fabricante (en inglés)
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. Datos de referencia
- Fabricante
- Fortinet
- Productos afectados
- FortiMail
- CVSS 3.1
- 9.8 (CRITICAL)
- Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C- Tipo de debilidad
- CWE-22: Path Traversal
- Publicada
- 1 de octubre de 2026
- En el catálogo KEV desde
- 1 de octubre de 2026
- Plazo agencias federales de EE. UU.
- 4 de octubre de 2026