First published · Last updated
CVE-2026-104286: Fortinet FortiMail Path Traversal Vulnerability
Fortinet FortiMail contains a path traversal and NULL-byte vulnerability that may allow an unauthenticated attacker to write arbitrary files via crafted HTTP or HTTPS requests. The source directs stakeholders to apply vendor mitigations and follow CISA BOD 26-04 and forensics triage guidance, or discontinue product use if mitigations are unavailable.
Categories: technology
Generated scores
Scores are based on the cited reporting and use a 1–10 scale. Read the methodology.
- Confidence
- 6/10
- Geographic reach
- 1/10
- Global importance
- 3/10
- Impact magnitude
- 4/10
- Positivity
- 2/10
- Urgency
- 6/10
Why it matters
May allow unauthenticated attackers to write arbitrary files on affected systems, so organizations must implement the vendor and CISA mitigation guidance.

