Loading market data...
← Back to CVE feed

CVE-2026-104286

CRITICAL CVSS 9.8 View on NVD ↗

Description

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

fortinet/fortimail
Published: Oct 01, 2026 20:17 UTC Modified: Oct 02, 2026 12:35 UTC