CVE-2026-104286
CRITICAL(9.8)KEV — Aktiv ausgenutztCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CVSS 9.8 — Kritisch
- Im CISA KEV-Katalog (aktiv ausgenutzt)
- Weniger als 24 Stunden alt
Erwähnungen (letzte 60 Tage)
CISA KEV
Bestätigt ausgenutzt
CVSS Score
9.8
Technische Schwere
SecBoard-Einordnung
CVE-2026-104286 betrifft Fortinet FortiMail und ist eine Path-Traversal-Schwachstelle. Sie ermöglicht es einem nicht authentifizierten Angreifer, beliebige Dateien auf dem System zu schreiben, indem manipulierte HTTP- oder HTTPS-Anfragen gesendet werden. Dies kann zu einer vollständigen Kompromittierung des Systems führen. Die Schwachstelle ist mit einem CVSS-Score von 9.8 als kritisch eingestuft und wird aktiv ausgenutzt, wie die Aufnahme in den CISA KEV-Katalog zeigt. Die aktive Ausnutzung unterstreicht die Dringlichkeit der Bedrohung und das hohe Risiko für betroffene Systeme. Security-Teams sollten umgehend alle FortiMail-Instanzen überprüfen, die in den betroffenen Versionen 8.0.0 bis 8.0.1, 7.6.0 bis 7.6.6, 7.4.0 bis 7.4.8 und 7.2.0 bis 7.2.9 laufen. Eine sofortige Patch-Implementierung oder die Anwendung verfügbarer Mitigationen ist dringend erforderlich, um eine Kompromittierung zu verhindern und die Systemintegrität zu gewährleisten.
KI-gestützte Einordnung auf Basis der NVD-Daten.
Beschreibung
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
Erkennung & Indikatoren
Ausnutzung
Aktiv ausgenutzt (CISA KEV). Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
Threat-Hunting-Queries
Detect attempts to write arbitrary files via HTTP/HTTPS requests, specifically looking for path traversal patterns in request parameters or headers.
Sentinel/Defender KQL
DeviceNetworkEvents
| where ActionType == "NetworkConnectionInitiated" or ActionType == "NetworkConnectionSuccessful"
| where RemotePort == 80 or RemotePort == 443
| where RemoteUrl contains "..%2f" or RemoteUrl contains "../"
| project TimeGenerated, DeviceName, InitiatingProcessFileName, RemoteIP, RemotePort, RemoteUrl, AdditionalFieldsSplunk SPL
index=* (sourcetype=web OR sourcetype=access_combined) (uri_path="%2e%2e%2f*" OR uri_path="../*") | table _time, host, src_ip, uri_path, methodSigma
title: FortiMail Path Traversal Attempt
id: 00000000-0000-0000-0000-000000000001
status: experimental
description: Detects attempts to exploit FortiMail path traversal vulnerability via HTTP/HTTPS requests.
author: SecBoard
date: 2026/10/01
logsource:
category: webserver
product: fortimail
detection:
selection:
c-uri|contains: # Adjust field name based on actual log source
- '../'
- '..%2f'
condition: selection
level: highElastic ES|QL
from logs-webserver-fortimail*
| where url.path : ("../", "..%2f")
| select @timestamp, host.name, source.ip, url.path, http.request.methodSecBoard-generated · behavioral · requires customization — Von SecBoard erzeugt und nicht in einer Zielumgebung validiert. Vor dem Einsatz an die eigene Protokollierung anpassen.