CVE-2026-104286
fortimail: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CVE-2026-104286)
Response & Mitigation
Why act now?
Prioritisation rationale
With a CVSS score of 9.8 (AV:N/AC:L/PR:N/UI:N/C:H/I:H/A:H), this vulnerability requires no authentication, no user interaction, and is exploitable over the network — the lowest possible bar for an attacker. Arbitrary file write primitives of this kind are routinely weaponised to drop web shells or overwrite configuration files, leading to full system compromise. FortiMail is widely deployed as a central email security gateway in NIS2-regulated and KRITIS environments, meaning a successful compromise threatens both the confidentiality of all mail traffic and the integrity of downstream mail-routing infrastructure. Organisations with FortiMail instances reachable from the internet should treat this as P1 and complete patching within the first business day; those behind strict perimeter controls should still patch within 72 hours and validate compensating controls are functioning in the interim.
Runbook · Step 1
Immediate response (0-24 h)
- Apply the vendor patch immediately: Affected versions are FortiMail 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8, and 7.2.0–7.2.9. Consult the Fortinet PSIRT advisory for the exact target version and upgrade without delay.
- Restrict external access to the admin interface: Block inbound access to port 443/TCP (and 8080/TCP if in use) from any source other than dedicated management networks — the web interface must not be reachable from the internet.
- Deploy path-traversal blocking at the perimeter: Configure your WAF or reverse proxy to reject requests containing
../,..%2F,%00, and double-encoded traversal sequences before they reach FortiMail, as an interim compensating control. - Run an immediate file-system integrity check: Baseline critical directories (
/etc,/var/www, FortiMail configuration paths) on all affected instances to detect any files already written by a potential attacker. - Verify lateral-movement firewall rules: Confirm that FortiMail hosts cannot initiate connections to internal servers beyond what mail relay requires — tighten egress rules if necessary.
Runbook · Step 2
Mitigation layers
- Network segmentation: Restrict ports 443/TCP and 8080/TCP to management VLANs via firewall ACLs; deny all internet-sourced connections to the FortiMail web interface.
- WAF/IPS rule: Enable a Snort/Suricata signature targeting path-traversal patterns in HTTP URIs — example:
alert http any any -> $FORTIMAIL_IP any (msg:"CVE-2026-104286 Path Traversal Attempt"; content:"../"; http_uri; nocase; sid:2026104286; rev:1;). Add a parallel rule for null-byte sequences (%00,\x00). - Reverse-proxy hardening: An nginx or HAProxy front-end should return HTTP 400 for any request containing null bytes or double-encoded traversal sequences, preventing them from ever reaching the FortiMail application layer.
- Least-privilege file-system controls: Ensure the OS user account running FortiMail processes has write access only to designated mail-data directories. Enforce this with SELinux or AppArmor policies where available.
- Centralise HTTP access logging: Enable verbose httpsd logging on FortiMail and forward logs to your SIEM in real time so that exploitation attempts are visible before a foothold is established.
Runbook · Step 3
Detection rules
- Web-server access logs (FortiMail httpsd): Alert on URI paths containing
../,%2e%2e,%252e, or%00— SPL:index=fortimail sourcetype=access_log uri_path IN ("*../*","*%2e%2e*","*%00*") | stats count by src_ip, uri_path - Sigma rule (unexpected file write): New or modified files in system directories on the FortiMail host — shape:
title: FortiMail Unexpected File Write; logsource: {product: linux, category: file_event}; detection: selection: {TargetFilename|contains: ['/etc/', '/var/www/', '/usr/lib/']} - Network telemetry (Zeek/Suricata): HTTP requests destined for the FortiMail IP where
uricontains..or a null-byte sequence originating from external source IPs — Zeek filter:http.log | where id.resp_h == <FORTIMAIL_IP> and uri contains "..". - Linux auditd:
syscall=openatorsyscall=writeevents outside/var/log/fortimailand/opt/fortimail/databy the FortiMail service UID — rule:-a always,exit -F arch=b64 -S openat -S write -F uid=<fortimail_uid> -k fortimail_filewrite. - EDR process ancestry: Child processes of
httpsdorsmtpdspawning shell interpreters (sh,bash,python) — alert on any unexpected parent-child relationship from these daemons.
Description
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
7.2.0 – 7.4.87.6.0 – 7.6.68.0.0 – 8.0.1Metrics
Show all metrics
Weakness classes (CWE)
CWE-22Base
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
cwe.mitre.org →
Public exploit references
Public proof-of-concepts and detection templates for this vulnerability. Maturity ranges from reported PoCs through working detection scripts up to fully weaponized exploit modules. NEOSEC mirrors the code internally for forensic analysis; externally we only link to the original sources.
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-10-07 18:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-104286","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"techni…
- SSVC: {"id":"CVE-2026-104286","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"techni…
- Initial Analysis2026-10-02 12:35 UTC· nvd@nist.gov
- CPE Configuration: OR *cpe:2.3:a:fortinet:fortimail:*:*:*:*:*:*:*:* versions from (including) 7.2.0 up to (including) 7.4.8 *cpe:2.3:a:fortinet:fortimail:*:*:*:*:*:*:*:* versions from (including) 7.6.0 up to (including) 7.6.6 *cpe:2.3:a:fortinet:fortimail:*:*:*:*:*:*:*:* versions from (including) 8.0.0 up to (including) 8.0.1
- Reference Type: Fortinet, Inc.: https://fortiguard.fortinet.com/psirt/FG-IR-26-175 Types: Mitigation, Vendor Advisory
- Reference Type: CISA-ADP: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-104286 Types: US Government Resource
- CVE Modified2026-10-02 04:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-104286","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"techni…
- SSVC: {"id":"CVE-2026-104286","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"techni…
- CVE CISA KEV Update2026-10-01 22:00 UTC· 9119a7d8-5eab-497f-8521-727c672e3725
- Date Added: 2026-10-01
- Due Date: 2026-10-01
- Required Action: 2026-10-01
- Vulnerability Name: 2026-10-01
- CVE Modified2026-10-01 21:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-104286","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technica…
- SSVC: {"id":"CVE-2026-104286","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"techni…
Linked advisories
- securityweek2026-10-02 08:07 UTCExploited Fortinet FortiMail Zero-Day Calls for Urgent Action
- ncsc-nl2026-10-02 07:21 UTCNCSC-2026-0398 [1.00] [M/H] Kwetsbaarheid verholpen in Fortinet FortiMail
- thehackernews2026-10-02 05:49 UTCCritical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
- cert-fr2026-10-02 00:00 UTCVulnérabilité dans Fortinet FortiMail (02 octobre 2026)
- bleepingcomputer2026-10-01 22:42 UTCFortinet warns of critical FortiMail flaw exploited in zero-day attacks