---
cve: "CVE-2026-104286"
severity: "CRITICAL"
cvss: 9.8
epss: ""
vendor: "Fortinet"
kev: true
exploited: true
published: "2026-10-01 19:17:38"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-10-02T18:59:33+02:00"
---

# CVE-2026-104286

> 9.8 CRITICAL · ⚠️ CISA KEV (0 Tage) · 🔓 Exploited

## Beschreibung

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

## CNA-Record (Kanon, cvelistV5)

- CNA: **fortinet**
- State: PUBLISHED
- Stand: 2026-10-01 20:10:11
- CNA-CVSS: **9.8** (`CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C`)

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **active**
  - Automatable: **yes**
  - Technical Impact: **total**

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Referenzen

- <https://fortiguard.fortinet.com/psirt/FG-IR-26-175>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-104286) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
