Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-104286

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.022
EPSS Ranking 81.9%
CVSS Severity
CVSS v3 Score 9.8
Proposed Action
Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
Ransomware Campaign
Unknown
Products affected by CVE-2026-104286


Contact Us

Shodan ® - All rights reserved