Back

CRITICAL KEV

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests

Published Oct 1, 2026 ·Due Oct 4, 2026

Description

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

Affected products

Remediation

Vendor solution

Upgrade to upcoming FortiMail version 8.0.1 or above Upgrade to upcoming FortiMail version 7.6.6 or above Upgrade to upcoming FortiMail version 7.4.8 or above Upgrade to upcoming FortiMail version 7.2.10 or above Upgrade to FortiRecorder version 7.6.1 or above Upgrade to FortiRecorder version 7.2.12 or above Upgrade to upcoming FortiRecorder version 7.0.7 or above

Metrics

Weaknesses (1)

References (2)

Change history (1)
  1. CISA ADP
    • SSVC exploitation changed from none to active
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner fortinet
Published Oct 1, 2026
Updated Oct 2, 2026
Reserved Oct 1, 2026
CISA Vulnrichment
Updated Oct 1, 2026
NVD
Status Awaiting Analysis
Modified Oct 2, 2026
Red Hat
Severity n/a
Public date n/a