{"uuid": "91594a1e-e5e5-4789-9f64-e088757548fe", "vulnerability": {"vulnId": "CVE-2026-104286", "altId": []}, "gcve": {"origin_uuid": "cce329bf-df49-4c6e-a027-80be2e6483bd", "object_uuid": "91594a1e-e5e5-4789-9f64-e088757548fe"}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-10-01T02:00:00+02:00"}, "timestamps": {"asserted_at": "2026-10-01T00:00:00+00:00", "recorded_at": "2026-10-02T06:52:36+00:00", "first_seen_at": "2026-10-01T00:00:00+00:00"}, "scope": {"notes": "Affected: Fortinet / FortiMail | Description: Improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. Customers are urged to disable the IBE feature support or disable access to the FortiMail management interface from the internet or limit the access only from trusted private network. | Exploitation type: unknown | CWEs: CWE-22, CWE-158 | Origin source: CNW | Notes: https://fortiguard.fortinet.com/psirt/FG-IR-26-175"}, "evidence": [{"type": "csirt_report", "source": "enisa-cnw-kev", "signal": "successful_exploitation", "confidence": 0.75, "details": {"cwes": ["CWE-22", "CWE-158"], "euvd": "EUVD-2026-91042", "notes": "https://fortiguard.fortinet.com/psirt/FG-IR-26-175", "catalog": "ENISA / EU CSIRTs Network (CNW) KEV JSON", "product": "FortiMail", "dateReported": "2026/10/01", "originSource": "CNW", "patchedSince": "", "vendorProject": "Fortinet", "exploitationType": ["unknown"], "vulnerabilityName": "", "threatActorsExploiting": []}}], "references": [{"id": "CVE-2026-104286", "url": "https://www.cve.org/CVERecord?id=CVE-2026-104286"}, {"id": "EUVD-2026-91042", "url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-91042"}, {"id": "source", "url": "https://fortiguard.fortinet.com/psirt/FG-IR-26-175"}]}
