Full Report
Fortinet security advisory (AV26-989)
Analysis Summary
# Vulnerability: Path Traversal in FortiMail (Pathname Limitation)
## CVE Details
- **CVE ID:** CVE-2026-104286
- **CVSS Score:** 9.8 (Critical) *(Based on CISA KEV listing and "Improper limitation of a pathname" categorization)*
- **CWE:** CWE-22 (Improper Limitation of a Pathname to a Restricted Directory / Path Traversal)
## Affected Systems
- **Products:** Fortinet FortiMail
- **Versions:**
- FortiMail 8.0: Versions prior to 8.0.2
- FortiMail 7.6: Versions prior to 7.6.7
- FortiMail 7.4: Versions prior to 7.4.9
- FortiMail 7.2: All versions (End of Engineering Support reached for this branch)
- **Configurations:** Systems running affected firmware versions with active web management or mail processing interfaces.
## Vulnerability Description
This vulnerability is an "Improper limitation of a pathname to a restricted directory" (Path Traversal). It allows an attacker to use specifically crafted input to access files and directories outside of the intended scope. In the context of FortiMail, this typically allows for unauthorized reading of sensitive system files or, in some instances, remote code execution (RCE) if an attacker can upload or manipulate files in critical system paths.
## Exploitation
- **Status:** **Exploited in the wild.** Added to CISA’s Known Exploited Vulnerabilities (KEV) Catalog on October 1, 2026.
- **Complexity:** Low
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** High (Potential access to configuration files and user data)
- **Integrity:** High (Potential for file modification or system takeover)
- **Availability:** High (Potential for system disruption)
## Remediation
### Patches
Fortinet recommends upgrading to the following versions:
- **FortiMail 8.0:** Upgrade to **8.0.2** or higher.
- **FortiMail 7.6:** Upgrade to **7.6.7** or higher.
- **FortiMail 7.4:** Upgrade to **7.4.9** or higher.
- **FortiMail 7.2:** This branch is no longer supported; users must **upgrade to the 7.4 branch** or above.
### Workarounds
No specific functional workaround is provided in the advisory. Immediate patching is the only recommended course of action due to active exploitation. Restricting access to the management interface to trusted internal networks is a general best practice.
## Detection
- **Indicators of Compromise:** Look for unusual directory traversal sequences (e.g., `../`, `..%2f`) in web server access logs. Monitor for unauthorized access to sensitive system files.
- **Detection methods and tools:** CISA KEV monitoring and vulnerability scanners updated with the latest Fortinet signatures.
## References
- Fortinet Advisory: hxxps[://]www[.]fortiguard[.]com/psirt/FG-IR-26-175
- Fortinet PSIRT: hxxps[://]www[.]fortiguard[.]com/psirt
- CISA KEV Catalog: hxxps[://]www[.]cisa[.]gov/known-exploited-vulnerabilities-catalog
- Government of Canada Advisory: hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/fortinet-security-advisory-av26-989