Summary
CVE-2026-104286 is a critical, actively exploited vulnerability in Fortinet FortiMail that combines an improper pathname limitation (path traversal) with improper neutralization of NULL bytes, allowing an unauthenticated remote attacker to write arbitrary files to the underlying system via crafted HTTP or HTTPS requests. Fortinet has confirmed exploitation in the wild, and CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog with an accelerated remediation deadline. The issue carries a CVSS v3.1 base score of 9.8 (Critical).
Technical details
- Root cause: The FortiMail management/web interface fails to properly restrict file paths supplied in requests (CWE-22) and does not correctly neutralize NULL bytes/characters within those paths (CWE-158), allowing path segments to escape the intended directory.
- Trigger conditions: An attacker sends specially crafted HTTP or HTTPS requests to the exposed FortiMail interface; no authentication or user interaction is required.
- Attack vector: Network-based (AV:N), low attack complexity, no privileges or user interaction required.
- Impact: Successful exploitation allows arbitrary file write on the underlying system, which can be leveraged to plant malicious files, modify configuration or application files, and potentially lead to further compromise (including remote code execution) of the appliance. Public reporting indicates the affected functionality sits within the GUI’s Identity Based Encryption (IBE) component.
Affected software
- FortiMail 8.0.0 through 8.0.1
- FortiMail 7.6.0 through 7.6.6
- FortiMail 7.4.0 through 7.4.8
- FortiMail 7.2.0 through 7.2.9
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Upgrade to a fixed release as soon as available:
- FortiMail 8.0.2 or later
- FortiMail 7.6.7 or later
- FortiMail 7.4.9 or later
- FortiMail 7.2.x has no planned fix on that branch — upgrade to 7.4.9 or later instead
- If immediate patching is not possible:
- Disable the Identity Based Encryption (IBE) feature via the CLI (
config system encryption ibeset status disable) - Restrict access to the FortiMail management/administrative interface to trusted internal networks only, and remove it from direct internet exposure
- Given confirmed in-the-wild exploitation, review logs and conduct forensic triage on any internet-exposed FortiMail management interfaces for signs of compromise
- Disable the Identity Based Encryption (IBE) feature via the CLI (

