Home · Wiki · Vulnerabilities & CVEs
type: cve · created: 2026-10-03 · updated: 2026-10-03 · tags: [cve, zero-day, fortinet, rce] · confidence: medium · severity: critical · affected_sectors: [global] · au_impact: false

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

Attribute Detail
CVE CVE-2026-104286
CVSS 9.8 (Critical) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vendor / product Fortinet — FortiMail
Reported 2026-10-01