Description
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
Published: 2026-10-01
Score: 9.8 Critical
EPSS: n/a
KEV: Yes
Impact: Arbitrary file write leading to potential remote code execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a path‑traversal flaw that allows an unauthenticated attacker to write arbitrary files to the underlying operating system via crafted HTTP or HTTPS requests. This capability can lead to full system compromise, enabling the planting of malicious binaries or configuration files that compromise confidentiality, integrity, and availability of the mail services. The flaw is rated CVSS 9.8, reflecting a critical severity and the high potential for exploitation.

Affected Systems

Fortinet FortiMail versions 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9 are affected. No other products are listed as impacted.

Risk and Exploitability

Because authentication is not required and the attack vector is standard HTTP/HTTPS traffic, an adversary can readily attempt to write to privileged locations. The CVSS score of 9.8 indicates the possibility of complete system takeover. EPSS is currently unavailable and the vulnerability is not catalogued in CISA KEV, but the high severity and lack of authentication requirements make it a serious exposure for any exposed FortiMail installation.

Generated by OpenCVE AI on October 1, 2026 at 21:24 UTC.

Remediation

Vendor Solution

Upgrade to upcoming FortiMail version 8.0.1 or above Upgrade to upcoming FortiMail version 7.6.6 or above Upgrade to upcoming FortiMail version 7.4.8 or above Upgrade to upcoming FortiMail version 7.2.10 or above Upgrade to FortiRecorder version 7.6.1 or above Upgrade to FortiRecorder version 7.2.12 or above Upgrade to upcoming FortiRecorder version 7.0.7 or above


OpenCVE Recommended Actions

  • Upgrade FortiMail to the latest supported release (e.g., 8.0.1 or later).
  • Upgrade FortiRecorder to the latest supported release (e.g., 7.6.1 or later).
  • Block or restrict incoming HTTP/HTTPS traffic to trusted sources until the patches are applied.

Generated by OpenCVE AI on October 1, 2026 at 21:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
Title Improper Pathname Restriction Allows Unauthenticated Arbitrary File Write in Fortinet FortiMail

Thu, 01 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2026-10-01T00:00:00+00:00', 'dueDate': '2026-10-04T00:00:00+00:00'}


Thu, 01 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
First Time appeared Fortinet
Fortinet fortimail
Weaknesses CWE-22
CPEs cpe:2.3:a:fortinet:fortimail:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimail:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimail:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimail:7.0.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimail:7.0.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimail:7.0.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimail:7.0.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimail:7.0.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimail:7.0.8:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimail:7.0.9:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimail:7.2.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimail:7.2.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimail:7.2.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimail:7.2.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimail:7.2.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimail:7.2.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimail:7.2.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimail:7.2.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimail:7.2.8:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimail:7.2.9:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimail:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimail:7.4.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimail:7.4.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimail:7.4.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimail:7.4.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimail:7.4.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimail:7.4.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimail:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimail:7.6.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimail:7.6.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimail:7.6.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimail:7.6.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimail:7.6.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimail:8.0.0:*:*:*:*:*:*:*
Vendors & Products Fortinet
Fortinet fortimail
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C'}


Subscriptions

Fortinet Fortimail
cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published:

Updated: 2026-10-01T20:10:11.148Z

Reserved: 2026-10-01T19:12:54.081Z

Link: CVE-2026-104286

cve-icon Vulnrichment

Updated: 2026-10-01T19:38:33.218Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-01T20:17:24.010

Modified: 2026-10-01T21:17:19.407

Link: CVE-2026-104286

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T21:30:13Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')