Fortinet FortiMail Path Traversal Vulnerability Allowing Unauthenticated Remote Code Execution

Release Date: 2nd October 2026 (Added 6th October 2026)

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilize the above product(s). This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-104286 is a critical path traversal vulnerability (CWE-22, with NULL byte handling, CWE-158) in Fortinet FortiMail. An unauthenticated remote attacker can send crafted requests to the management or webmail (Identity-Based Encryption, IBE) interface to write arbitrary files to the system, which can lead to remote code execution. CVSS score: 9.8 (Critical). Fortinet tracks it as FG-IR-26-175.

Reference

  1. https://fortiguard.fortinet.com/psirt/FG-IR-26-175
  2. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  3. https://nvd.nist.gov/vuln/detail/CVE-2026-104286