Fortinet FortiMail Path Traversal
Fortinet FortiMail Path Traversal
Summary
Fortinet disclosed a Path Traversal in FortiMail that lets an unauthenticated attacker write files onto the underlying system through crafted web requests. Arbitrary file write on an internet-facing mail gateway can lead to command execution and full appliance compromise.
Affected Systems and/or Applications
Fortinet FortiMail:
The affected endpoint is the GUI (webmail interface). Fortinet's workarounds centre on the Identity-Based Encryption (IBE) feature and the /ibe path.
Technical Details
Vulnerability Mechanism
The flaw is a path traversal combined with null byte handling in how FortiMail processes incoming HTTP/HTTPS requests. It lets an unauthenticated attacker write files outside the intended directory. Fortinet's mitigations target IBE. Fortinet's suggested WAF control is to block POST requests to /ibe containing ../.
Observed Exploitation Path
Exploitation in the wild is confirmed by Fortinet and CISA. The following was observed:
- Fortinet publishes IoCs that include the IP addresses
79.141.169.187and45.129.0.192. - Fortinet lists system event log artefacts: cron entries of the form
(root) CMD (/bin/sh -c 'O=/migadmin ..., the messageUser admin logged out from (null)., and an archive account added with remote IP79.141.169.187. - Fortinet lists encryption log artefacts: Base64 decoding failure messages and failed internal user logins.
Mitigation
Limit Exposure
Fortinet workarounds (confirmed: FortiGuard):
- Disable IBE from the GUI or CLI:
config system encryption ibe
set status disable
end- Restrict access to the webmail interface to trusted networks.
- Deploy a WAF rule that blocks POST requests to
/ibecontaining../.
Patch/Upgrade
Upgrade to the fixed version for the branch listed in the table above (8.0.2+, 7.6.7+, 7.4.9+). Move 7.2.x to branch 7.4 or above. Verify the version list on FG-IR-26-175 first, because other records disagree (see Affected Systems).
What the Cyber Fusion Center is Doing
The CFC is monitoring the situation and analyzing the case to identify potential threat-hunting campaigns. This advisory will be updated if required.
References
- Fortinet PSIRT FG-IR-26-175: https://fortiguard.fortinet.com/psirt/FG-IR-26-175
- watchTowr FAQ: https://watchtowr.com/intelligence/fortinet-fortimail-cve-2026-104286-faq/
- Tenable CVE page: https://www.tenable.com/cve/CVE-2026-104286





.avif)





.webp)