Path traversal in FortiMail - CVE-2026-104286
Published: October 1, 2026
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The vulnerability exists due to improper input validation when handling URLs within the IBE feature in the FortiMail management interface. A remote non-authenticated attacker can write arbitrary files on the underlying system via specially crafted HTTP requests, which may result in full system compromise.
Note, the vulnerability is being actively exploited in the wild.
Affected software
How to mitigate CVE-2026-104286
Vendor plans to address this vulnerability in the upcoming versions: 7.4.9,7.6.7, and 8.0.2.
As a workaround it is recommended to disable the IBE feature support or restrict access to the FortiMail management interface.