CVE-2026-104286: Fortinet FortiMail Path Traversal Vulnerability
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
Other sources
Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Fortinet FortiMailto a version that resolves this vulnerability.Fixed in 7.2.10 - Upgrade
Upgrade
Fortinet FortiMailto a version that resolves this vulnerability.Fixed in 7.4.8 - Upgrade
Upgrade
Fortinet FortiMailto a version that resolves this vulnerability.Fixed in 7.6.6 - Upgrade
Upgrade
Fortinet FortiMailto a version that resolves this vulnerability.Fixed in 8.0.1 - Upgrade
Upgrade
Fortinet FortiRecorderto a version that resolves this vulnerability.Fixed in 7.0.7 - Upgrade
Upgrade
Fortinet FortiRecorderto a version that resolves this vulnerability.Fixed in 7.2.12 - Upgrade
Upgrade
Fortinet FortiRecorderto a version that resolves this vulnerability.Fixed in 7.6.1 - Compensating control
Discontinue use of FortiMail if mitigations are unavailable.
Event History
Frequently Asked Questions
Which FortiMail releases are affected?
Affected releases are FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9.
Does exploitation require an account or user interaction?
No. The vulnerability can be exploited by an unauthenticated attacker and does not require user interaction.
How can an attacker reach the vulnerable functionality?
An attacker can send crafted HTTP or HTTPS requests to the affected FortiMail system. The issue permits arbitrary file writes on the underlying system through path traversal.