CVE-2026-104286 Fortinet FortiMail: Path Traversal
9.8 KEV Attivamente sfruttata secondo la CISA
Analisi su rafaelpfister.ch
Descrizione del produttore (in inglese)
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. Dati di riferimento
- Produttore
- Fortinet
- Prodotti interessati
- FortiMail
- CVSS 3.1
- 9.8 (CRITICAL)
- Vettore
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C- Tipo di debolezza
- CWE-22: Path Traversal
- Pubblicata
- 1 ottobre 2026
- Nel catalogo KEV dal
- 1 ottobre 2026
- Scadenza enti federali USA
- 4 ottobre 2026