EUVD Vulnerability Catalog Actively Exploited (KEV)

EUVD-2026-91042

Severity: CRITICAL Base Score: 9.8 CVSS Version: 3.1

Vulnerability Description

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

CVSS Vector Analysis

Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C

▪ Attack Vector (AV): Network
▪ Attack Complexity (AC): Low
▪ Privileges Required (PR): None
▪ User Interaction (UI): None
▪ Scope (S): Unchanged
▪ Confidentiality Impact (C): High
▪ Integrity Impact (I): High
▪ Availability Impact (A): High
▪ E: P
▪ RL: O
▪ RC: Changed

Affected Vendors & Systems

Vendor Fortinet

References & Advisory Links

Metadata Profile

Database Authority

European Union Agency for Cybersecurity (ENISA) EUVD

Assigner

fortinet

EPSS Probability

0

Known Aliases
CVE-2026-104286
Published On

2026-10-01

Last Updated

2026-10-01

Exploited Since

2026-10-01