Fortinet FortiMail Path Traversal Vulnerability Allowing Unauthenticated Remote Code Execution
Release Date: 2nd October 2026 (Added 6th October 2026)
Impact : CRITICAL
TLP Rating: Clear 
The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.
This alert is relevant to Organizations and System/Network administrators that utilize the above product(s). This alert is intended to be understood by technical users and systems administrators.
What is it?
CVE-2026-104286 is a critical path traversal vulnerability (CWE-22, with NULL byte handling, CWE-158) in Fortinet FortiMail. An unauthenticated remote attacker can send crafted requests to the management or webmail (Identity-Based Encryption, IBE) interface to write arbitrary files to the system, which can lead to remote code execution. CVSS score: 9.8 (Critical). Fortinet tracks it as FG-IR-26-175.
What are the systems affected?
The following FortiMail versions are affected:
FortiMail 8.0.0 through 8.0.1 – (Affected)
FortiMail 7.6.0 through 7.6.6 – (Affected)
FortiMail 7.4.0 through 7.4.8 – (Affected)
FortiMail 7.2.0 through 7.2.9 – (Affected)
Not affected / patched version:
Fixed releases announced by Fortinet: FortiMail 8.0.2, 7.6.7 and 7.4.9, once available – (Not affected)
FortiMail 7.2 has no planned fix; migrate to 7.4 or later
What does this mean?
Successful exploitation may allow attackers to:
- Write arbitrary files to the mail gateway without authentication
- Execute arbitrary code on the FortiMail appliance, leading to full compromise of the device
- Access, alter or redirect email traffic, and use the appliance as a foothold into the internal network
Mitigation process?
CERTVU recommends the following:
-
Apply the Fixed Release as Soon as Available
Upgrade to FortiMail 8.0.2, 7.6.7 or 7.4.9 as applicable, and migrate FortiMail 7.2 to 7.4 or later. Check Fortinet advisory FG-IR-26-175 for the current availability. -
Apply Workarounds Until Patched
-
Add Compensating Controls
-
Hunt for Compromise
Reference
- https://fortiguard.fortinet.com/psirt/FG-IR-26-175
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://nvd.nist.gov/vuln/detail/CVE-2026-104286
- Download advisory (English): Fortinet FortiMail Path Traversal Vulnerability