Full Report
No login required, exploitation underway, and some admins are still waiting for patches
Analysis Summary
# Vulnerability: FortiMail Critical Unauthenticated File Write
## CVE Details
- **CVE ID:** CVE-2026-104286
- **CVSS Score:** 9.8 (Critical)
- **CWE:** CWE-22 (Path Traversal) / CWE-158 (Improper Handling of Null Characters)
## Affected Systems
- **Products:** Fortinet FortiMail (Email Security Platform)
- **Versions:**
- 8.0.0 through 8.0.1
- 7.6.0 through 7.6.6
- 7.4.0 through 7.4.8
- 7.2.0 through 7.2.9
- **Configurations:** Systems with the web management interface exposed to the internet or untrusted networks.
## Vulnerability Description
CVE-2026-104286 is a critical vulnerability involving path traversal and the improper handling of null characters within the FortiMail web interface. An unauthenticated, remote attacker can send specially crafted HTTP or HTTPS requests to the appliance to perform arbitrary file writes. By writing files to sensitive system locations, an attacker can achieve remote code execution (RCE) or command execution on the underlying operating system.
## Exploitation
- **Status:** Exploited in the wild (Confirmed by Fortinet and CISA).
- **Complexity:** Low (No authentication required).
- **Attack Vector:** Network (HTTP/HTTPS).
## Impact
- **Confidentiality:** High (Potential for full system compromise and data theft).
- **Integrity:** High (Ability to write/modify arbitrary files and configurations).
- **Availability:** High (Potential for system takeover or service disruption).
## Remediation
### Patches
Fortinet has listed fixes for several branches as **"upcoming."** Administrators must monitor the FortiGuard PSIRT portal for the release of the following versions:
- FortiMail 8.0.2 (or higher)
- FortiMail 7.6.7 (or higher)
- FortiMail 7.4.9 (or higher)
- FortiMail 7.2.10 (or higher)
### Workarounds
- **Disable Features:** Disable "Identity Based Encryption" (IBE) if it is not business-essential.
- **Network Hardening:** Ensure the FortiMail management interface is not reachable from the public internet.
- **Access Control:** Restrict access to the management interface to specific, trusted private networks or management VLANs.
## Detection
- **Indicators of Compromise (IoCs):**
- Presence of suspicious or unauthorized files in the system directories.
- Unexpected configuration changes.
- Log entries showing HTTP/HTTPS requests containing null characters (`%00`) or path traversal sequences (`../`).
- **Detection methods and tools:**
- Conduct forensic triage as mandated by CISA (for applicable agencies).
- Review web server logs for the IP addresses published in the Fortinet advisory (refer to the official PSIRT link).
## References
- **Vendor Advisory:** hxxps[://]fortiguard[.]fortinet[.]com/psirt/FG-IR-26-175
- **CISA KEV Catalog:** hxxps[://]www[.]cisa[.]gov/known-exploited-vulnerabilities-catalog