CVE-2026-104286
Known Exploited Vulnerability Entry ENISA
Entry Details
Confirmed Exploited2026-10-01 02:00 CEST
Timestamps
2026-10-01
2026-10-01
Scope
Affected: Fortinet / FortiMail | Description: Improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. Customers are urged to disable the IBE feature support or disable access to the FortiMail management interface from the internet or limit the access only from trusted private network. | Exploitation type: unknown | CWEs: CWE-22, CWE-158 | Origin source: CNW | Notes: https://fortiguard.fortinet.com/psirt/FG-IR-26-175
References
- {'id': 'CVE-2026-104286', 'url': 'https://www.cve.org/CVERecord?id=CVE-2026-104286'}
- {'id': 'EUVD-2026-91042', 'url': 'https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-91042'}
- {'id': 'source', 'url': 'https://fortiguard.fortinet.com/psirt/FG-IR-26-175'}
91594a1e-e5e5-4789-9f64-e088757548fe
ENISA
cce329bf-df49-4c6e-a027-80be2e6483bd
2026-10-02 08:52 CEST
2026-10-02 08:52 CEST
Evidence
1| Type | Source | Signal | Confidence | Details | GCVE Metadata |
|---|---|---|---|---|---|
| csirt_report | enisa-cnw-kev | successful_exploitation | 0.75 |
View details
|
- |