**CVE-2026-104286 – Critical FortiMail Path Traversal Vulnerability

TL;DR

  • Critical severity (CVSS 9.8) path traversal in Fortinet FortiMail.
  • Unauthenticated attackers can write arbitrary files via crafted HTTP/HTTPS requests.
  • CISA KEV lists it as actively exploited; federal patch deadline 2026-10-04.
  • Affected versions: 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8, 7.2.0–7.2.9.
  • Immediate action: apply patch or disable IBE and restrict management interface.

Overview

The CVE-2026-104286 vulnerability is a CWE-22 improper limitation of a pathname to a restricted directory (path traversal) in Fortinet FortiMail. It allows an unauthenticated attacker to write arbitrary files on the underlying system through specially crafted HTTP or HTTPS requests. The flaw was disclosed on 2026-10-01 and added to the CISA KEV the same day, indicating confirmed active exploitation in the wild.

Technical Details

The vulnerability resides in the web interface of FortiMail. By sending a request with a crafted path, an attacker can traverse directories and place files outside the intended web root. The CVSS 3.1 vector string is:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

This yields a base score of 9.8, classifying it as Critical. The attack requires no authentication, no user interaction, and has low complexity, making it highly exploitable.

Severity & Impact

With a CVSS 9.8 rating, the vulnerability threatens confidentiality, integrity, and availability. An attacker can:

  • Write malicious scripts or configuration files that lead to remote code execution.
  • Overwrite system binaries or startup scripts, causing denial‑of‑service.
  • Establish persistence by dropping backdoors.

Because FortiMail often sits at the email gateway boundary, successful exploitation can compromise the entire corporate network.

Affected Products

The flaw impacts the following FortiMail releases:

ProductAffected Versions
FortiMail 8.08.0.0 – 8.0.1
FortiMail 7.67.6.0 – 7.6.6
FortiMail 7.47.4.0 – 7.4.8
FortiMail 7.27.2.0 – 7.2.9

For the complete list of affected builds, see the CVE page on VulnSocial.

Actionable Insights / What to Do

  1. Identify all internet‑facing FortiMail appliances and verify their version.
  2. Prioritize patching for those running any affected release.
  3. Monitor logs for anomalous HTTP/HTTPS requests containing path traversal sequences (e.g., ../, %2e%2e%2f).
  4. Hunt for unexpected files in web‑accessible directories, especially under /var/www/ or /opt/.
  5. Report any suspicious findings to your incident response team.

Remediation & Mitigation

  1. Apply the official patch from Fortinet as soon as it becomes available (target versions 8.0.2, 7.6.7, 7.4.9+, or migrate 7.2 to 7.4+).
  2. If a patch cannot be deployed immediately, disable the Identity‑Based Encryption (IBE) feature:
    config system encryption ibe
    set status disable
    end
    
  3. Restrict management interface access to trusted IP ranges; avoid exposing the web UI to the internet.
  4. Enable intrusion detection/prevention signatures for path traversal attempts.
  5. Perform a full system integrity check after applying the mitigation.

References

#CVE #Critical #RCE #CISAKEV #Fortinet #FortiMail #CVE2026104286