CVE-2026-104286
October 5, 2026
·
0
Minutes Read

Fortinet FortiMail Path Traversal

Security Advisory
Advisory
October 5, 2026
·
0
Minutes Read

Fortinet FortiMail Path Traversal

Security Advisory
Advisory
October 5, 2026
·
0
Minutes Read
Kudelski Security Team
Find out more
table of contents
Share on
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Summary

Fortinet disclosed a Path Traversal in FortiMail that lets an unauthenticated attacker write files onto the underlying system through crafted web requests. Arbitrary file write on an internet-facing mail gateway can lead to command execution and full appliance compromise.

Affected Systems and/or Applications

Fortinet FortiMail:

Branch Affected Fixed per FortiGuard
8.0 8.0.0 – 8.0.1 8.0.2 and later
7.6 7.6.0 – 7.6.6 7.6.7 and later
7.4 7.4.0 – 7.4.8 7.4.9 and later
7.2 7.2.0 – 7.2.9 Migrate to branch 7.4 or above

The affected endpoint is the GUI (webmail interface). Fortinet's workarounds centre on the Identity-Based Encryption (IBE) feature and the /ibe path.

Technical Details

Vulnerability Mechanism

The flaw is a path traversal combined with null byte handling in how FortiMail processes incoming HTTP/HTTPS requests. It lets an unauthenticated attacker write files outside the intended directory. Fortinet's mitigations target IBE. Fortinet's suggested WAF control is to block POST requests to /ibe containing ../.

Observed Exploitation Path

Exploitation in the wild is confirmed by Fortinet and CISA. The following was observed:

  • Fortinet publishes IoCs that include the IP addresses 79.141.169.187 and 45.129.0.192.
  • Fortinet lists system event log artefacts: cron entries of the form (root) CMD (/bin/sh -c 'O=/migadmin ..., the message User admin logged out from (null)., and an archive account added with remote IP 79.141.169.187.
  • Fortinet lists encryption log artefacts: Base64 decoding failure messages and failed internal user logins.

Mitigation

Limit Exposure

Fortinet workarounds (confirmed: FortiGuard):

  • Disable IBE from the GUI or CLI:
  • config system encryption ibe
    set status disable
    end
  • Restrict access to the webmail interface to trusted networks.
  • Deploy a WAF rule that blocks POST requests to /ibe containing ../.

Patch/Upgrade

Upgrade to the fixed version for the branch listed in the table above (8.0.2+, 7.6.7+, 7.4.9+). Move 7.2.x to branch 7.4 or above. Verify the version list on FG-IR-26-175 first, because other records disagree (see Affected Systems).

What the Cyber Fusion Center is Doing

The CFC is monitoring the situation and analyzing the case to identify potential threat-hunting campaigns. This advisory will be updated if required.

References

Related Post