## Overview
Fortinet disclosed a critical vulnerability in FortiMail, tracked as CVE-2026-104286. This flaw affects FortiMail versions 8.0.0 to 8.0.1, 7.6.0 to 7.6.6, 7.4.0 to 7.4.8, and 7.2.0 to 7.2.9. An unauthenticated attacker can exploit this vulnerability to write arbitrary files on the underlying system.
## Technical Details
The vulnerability arises from an improper limitation of pathnames to a restricted directory, commonly known as a path traversal issue. Attackers can craft specific HTTP or HTTPS requests to manipulate file paths. This allows them to bypass security restrictions and write files to locations they should not access. The severity of this vulnerability is rated at 9.8 on the CVSS scale, indicating a critical risk to affected systems.
## Impact
Successful exploitation of CVE-2026-104286 can lead to unauthorized file creation on the server. This could compromise the integrity of the system, allowing attackers to execute malicious code or access sensitive data. Given the nature of the vulnerability, it poses a significant threat to organizations using the affected FortiMail versions.
## Mitigation
Defenders should prioritize updating FortiMail to the latest versions as soon as possible. Fortinet has released patches that address this vulnerability. Ensure that all instances of FortiMail are updated to versions beyond the affected ranges. Additionally, implement network security measures to monitor and restrict unauthorized access attempts.
CSURFACE Threat Sensor