CVE-2026-104286

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8,

Severity
Critical 9.8
CVSS 3.1
Remote · no auth what this means
Exploited
Yes — in CISA KEV
Added Oct 1, 2026
EPSS
—
Discovered by
Vendor
Vendor advisory acknowledgement
Published
Oct 1, 2026
Assigned by fortinet

Description

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

Weakness: CWE-22

Affected products

Vendor Product Category Matched by
Fortinet FortiMail Email Security cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiMail

Credit

Internally discovered and reported by Gwendal Guégniaud of Fortinet Product Security team

Vendor remediation

Upgrade to upcoming FortiMail version 8.0.1 or above Upgrade to upcoming FortiMail version 7.6.6 or above Upgrade to upcoming FortiMail version 7.4.8 or above Upgrade to upcoming FortiMail version 7.2.10 or above Upgrade to FortiRecorder version 7.6.1 or above Upgrade to FortiRecorder version 7.2.12 or above Upgrade to upcoming FortiRecorder version 7.0.7 or above

Something wrong here?