Path traversal in FortiMail - CVE-2026-104286

 

Path traversal in FortiMail - CVE-2026-104286

Published: October 1, 2026


Vulnerability identifier: #VU153085
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-104286
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The vulnerability exists due to improper input validation when handling URLs within the IBE feature in the FortiMail management interface. A remote non-authenticated attacker can write arbitrary files on the underlying system via specially crafted HTTP requests, which may result in full system compromise. 

Note, the vulnerability is being actively exploited in the wild.


Affected software

FortiMail

How to mitigate CVE-2026-104286

Vendor plans to address this vulnerability in the upcoming versions: 7.4.9,7.6.7, and 8.0.2.

As a workaround it is recommended to disable the IBE feature support or restrict access to the FortiMail management interface.



External References

Related Security Bulletins