CVE-2026-104286: Fortinet FortiMail Unauthenticated Path Traversal Leading to Arbitrary File Write
A critical path traversal vulnerability (CVE-2026-104286) in Fortinet FortiMail allows unauthenticated attackers to write arbitrary files to the underlying system via crafted HTTP/HTTPS requests. This flaw, with a CVSSv3.1 score of 9.8, affects multiple FortiMail versions and poses a significant risk of remote code execution or system compromise. Immediate patching is recommended.
Overview
CVE-2026-104286 is a critical path traversal vulnerability affecting Fortinet FortiMail appliances. This flaw allows an unauthenticated attacker to write arbitrary files to the underlying system by sending specially crafted HTTP or HTTPS requests. Given the unauthenticated nature and potential for remote code execution, this vulnerability presents a severe risk to affected organizations.
Technical Analysis
- CVE ID:
CVE-2026-104286 - Vulnerability Type: Improper limitation of a pathname to a restricted directory (‘path traversal’) (
CWE-22) and improper neutralization of NULL byte or NULL character. - Affected Products: Fortinet FortiMail
- Versions 8.0.0 through 8.0.1
- Versions 7.6.0 through 7.6.6
- Versions 7.4.0 through 7.4.8
- Versions 7.2.0 through 7.2.9
- Attack Vector: Unauthenticated attackers can exploit this vulnerability by sending crafted HTTP or HTTPS requests to the FortiMail appliance.
- Impact: Successful exploitation allows an attacker to write arbitrary files to the underlying operating system. This could lead to remote code execution (e.g., by dropping a webshell), denial of service, or further system compromise.
- CVSS v3.1 Score: 9.8 (CRITICAL)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Vector:
Detection
- Monitor FortiMail web access logs for unusual request patterns, specifically
GETorPOSTrequests containing path traversal sequences like../,..%2f,..%c0%af, or other URL-encoded variations. - Look for requests targeting unusual directories or file types in the web root that are not part of normal FortiMail operation.
- Monitor FortiMail system logs for any unauthorized file write attempts or unexpected process creations, though direct host-level logging may be limited on appliances.
Sigma Detection Rules
Fortinet FortiMail Path Traversal Attempt (CVE-2026-104286)
title: Fortinet FortiMail Path Traversal Attempt (CVE-2026-104286)
id: 81a0e1b1-2a1f-4c7e-b7d5-f8a0e1b12a1f
status: experimental
description: Detects attempts to exploit CVE-2026-104286 in Fortinet FortiMail by looking for path traversal patterns in HTTP/HTTPS request URIs or query strings.
logsource:
category: webserver
product: fortimail
detection:
selection:
- cs-uri-stem|contains:
- '../'
- '..%2f'
- '..%c0%af'
- '..%252f'
- cs-uri-query|contains:
- '../'
- '..%2f'
- '..%c0%af'
- '..%252f'
condition: selection
level: high
Mitigations
- Apply the latest security patches from Fortinet as soon as they become available. Refer to FortiGuard PSIRT Advisory
FG-IR-26-175for specific patch versions. - Restrict network access to the FortiMail administration interface and web services to only trusted IP addresses and necessary internal networks.
- Implement a Web Application Firewall (WAF) in front of the FortiMail appliance to detect and block path traversal attempts, if feasible.
- Regularly back up FortiMail configurations and data to facilitate recovery in case of compromise.
References
- https://fortiguard.fortinet.com/psirt/FG-IR-26-175
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-104286
- https://nvd.nist.gov/vuln/detail/CVE-2026-104286
Indicators of Compromise
No public IOCs available at time of writing.
MITRE ATT&CK
T1505.003— Web Shell
Generated by
gemini-2.5-flash ·1,790 input / 1,259 output tokens ·
Reviewed and approved by a human analyst before publication