Sceawere

Vulnerability Detail

CVE-2026-104286UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

FortiMail Path Traversal Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
1d ago
Vendor
Fortinet
Product
FortiMail
Attack Type
Execute unauthorized code or commands
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-10-01T20:17:24.010Z",
  "pubdate": "2026-10-01T20:17:24.010Z",
  "executiveSummary": "A critical path traversal vulnerability exists in multiple versions of Fortinet FortiMail, classified as an improper limitation of a pathname to a restricted directory (CWE-22).\nThis vulnerability allows an unauthenticated, remote attacker to perform arbitrary file write operations on the underlying system by sending specifically crafted HTTP or HTTPS requests.\nSuccessful exploitation bypasses security controls, potentially granting an attacker the ability to overwrite system configuration files, inject malicious scripts, or modify binaries.\nAffected products include FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9.\nThe risk implication is severe, as the vulnerability does not require authentication and provides a direct vector for persistent system compromise, privilege escalation, or full remote code execution depending on the file targets.\nOrganizations using the identified versions are at significant risk and should prioritize addressing this exposure to prevent unauthorized system modification.",
  "technicalDetails": "The root cause of this vulnerability is the failure of the FortiMail web server component to properly sanitize input parameters that control file path generation or redirection. The application does not effectively restrict user-supplied input when defining target paths for write operations.\nThe exploitation method leverages path traversal sequences (such as '../') within crafted HTTP or HTTPS requests directed at vulnerable endpoints. Because the application fails to validate the absolute or relative path against a predefined document root or restricted sandbox directory, an attacker can escape the intended directory structure.\nThe attack flow begins with the attacker crafting a request where the input parameter contains traversal characters designed to navigate outside the secure operational directory. When the FortiMail system processes this input to determine where to store or save incoming data, it interprets the malicious path. Consequently, the application writes the payload of the request into an arbitrary location on the filesystem.\nBecause the vulnerability is exploitable via HTTP or HTTPS, it is reachable over the network without requiring any prior authentication. The attacker possesses the ability to target any location on the disk that the service account running the FortiMail process has permissions to access.\nThe post-exploitation impact is critical. By overwriting existing system configuration files, an attacker can manipulate authentication bypasses, disable security logging, or redirect traffic flow. If the attacker targets executable binaries or cron directories, they can achieve persistent remote code execution, effectively gaining full control over the appliance.\nThe affected versions include a wide range of the FortiMail software stack: 8.0.0-8.0.1, 7.6.0-7.6.6, 7.4.0-7.4.8, and 7.2.0-7.2.9. These versions lack the necessary input validation checks to prevent the traversal, making them susceptible to remote file manipulation by any actor with network access to the web interface."
}
CVE-2026-104286: FortiMail Path Traversal Vulnerability (CRITICAL Severity, CVSS: 9.8) | Sceawere