Critical FortiMail Flaw Enables Pre‑Auth File Write, Opening the Door to Full Compromise
Unauthenticated attackers can write arbitrary files on FortiMail appliances via crafted HTTP/HTTPS requests.
On a Linux‑based perimeter email gateway, arbitrary file write = practical remote code execution (RCE).
This flaw is confirmed exploited in the wild and added to CISA’s KEV catalog.
CVE‑2026‑104286 combines two weaknesses:
Path Traversal (CWE‑22) — FortiMail fails to sanitize directory traversal sequences (
../, encoded variants).Improper NULL Byte Neutralization (CWE‑158) —
%00truncates paths at the OS level, bypassing validation.
Together, these allow attackers to write files anywhere on the filesystem through the web‑facing management or service interface.
Once an attacker can write arbitrary files, they can:
Drop a webshell into a served directory
Modify cron jobs
Overwrite binaries invoked by privileged services
Add SSH authorized_keys
Plant persistence in FortiMail’s internal daemons
Security researchers emphasize that this should be treated as an active incident, not a routine patch cycle item. [^2]
Affected Versions
FortiMail versions confirmed vulnerable:
8.0.0 – 8.0.1
7.6.0 – 7.6.6
7.4.0 – 7.4.8
7.2.0 – 7.2.9
Fix Versions (upcoming at disclosure)
8.0.2
7.6.7
7.4.9
For 7.2, Fortinet recommends upgrading to 7.4+.
Workarounds (Until Patched)
Fortinet recommends:
1. Disable IBE (Identity‑Based Encryption)
config system encryption ibe
set status disable
end2. Restrict Management Interface Exposure
Remove internet access to the FortiMail management interface
Or restrict access to trusted private networks only
Indicators of Compromise (IOCs)
Fortinet published file‑level indicators showing attacker modifications:
Added Files
/data/lib/liblog.so/data/bin/webconsole/data/bin/mailservice/data/etc/ld.so.preload
Modified Files
/bin/smit/data/etc/httpd.conf/data/migadmin.tar.gz
Hashes for these files were provided for verification.
Because FortiMail is typically:
Internet‑facing
A perimeter security appliance
Poorly monitored by EDR
Holding admin credentials and mail‑flow trust
…a compromise here is a direct pivot point into the internal environment.
Security analysts recommend treating all exposed FortiMail systems as potentially compromised.
Immediate Actions for Your Environment
Apply workarounds immediately (disable IBE, restrict management access).
Upgrade to fixed firmware as soon as available.
Hunt for IOCs listed above.
Review logs for suspicious file writes or unexpected HTTPS requests to admin/webmail endpoints.
Check for persistence (webshells, cron jobs, modified binaries).
Assume compromise if the device was internet‑exposed and unpatched.
.png)
Comments
Post a Comment