CVE-2026-104286 Fortinet FortiMail: Path Traversal
9.8 KEV Activement exploitée selon la CISA
Analyse sur rafaelpfister.ch
Description de l'éditeur (en anglais)
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. Données de référence
- Éditeur
- Fortinet
- Produits concernés
- FortiMail
- CVSS 3.1
- 9.8 (CRITICAL)
- Vecteur
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C- Type de faiblesse
- CWE-22: Path Traversal
- Publiée
- 1 octobre 2026
- Dans le catalogue KEV depuis
- 1 octobre 2026
- Échéance administrations fédérales US
- 4 octobre 2026