---
id: CVE-2026-104286
title: >-
  An improper limitation of a pathname to a restricted directory ('path
  traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail
  7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through
  7.2.9 may al…
summary: >-
  An improper limitation of a pathname to a restricted directory ('path
  traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail
  7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through
  7.2.9 may al…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-22
vendor: Fortinet
product: FortiMail
affected:
  - FortiMail 8.0.0
  - FortiMail >= 7.6.0 <= 7.6.5
  - FortiMail >= 7.4.0 <= 7.4.6
  - FortiMail >= 7.2.0 <= 7.2.9
  - FortiMail >= 7.0.0 <= 7.0.9
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T21:17:19.407'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104286'
references:
  - url: 'https://fortiguard.fortinet.com/psirt/FG-IR-26-175'
    label: psirt@fortinet.com
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-104286
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - in-the-wild
  - exploit-available
exploited: true
exploitAvailable: true
ssvc:
  exploitation: active
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-10-01T20:02:06.190902Z'
ingestedAt: '2026-10-01T19:58:57.565Z'
---

## Overview

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
