CVE-2026-104286

Summary

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

Affected Software

VendorProductVersion RangeStatus
FortinetFortiMail8.0.0affected
FortinetFortiMail7.6.0 <= 7.6.5affected
FortinetFortiMail7.4.0 <= 7.4.6affected
FortinetFortiMail7.2.0 <= 7.2.9affected
FortinetFortiMail7.0.0 <= 7.0.9affected

Weaknesses

  • CWE-22: Execute unauthorized code or commands

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: active
    • Automatable: yes
    • Technical Impact: total

Additional References

References