CVE-2026-104286: 
Fortimail 취약성 분석 및 완화

개요

CVE-2026-104286 is a critical path traversal vulnerability (CWE-22 / CWE-158) in Fortinet FortiMail that allows unauthenticated remote attackers to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. The vulnerability affects FortiMail versions 7.2.0–7.2.9, 7.4.0–7.4.8, 7.6.0–7.6.6, 8.0.0–8.0.1, and also 7.0.0–7.0.9 per NVD data. It was publicly disclosed on October 1, 2026, and was immediately added to CISA's Known Exploited Vulnerabilities (KEV) catalog the same day due to confirmed in-the-wild exploitation. It carries a CVSS v3.1 base score of 9.8 (Critical) (FortiGuard Advisory, CISA KEV, GitHub Advisory).

기술적 세부 사항

The vulnerability stems from two combined weaknesses: improper limitation of a pathname to a restricted directory (CWE-22) and improper neutralization of NULL bytes or NULL characters (CWE-158) in FortiMail's IBE (Identity-Based Encryption) feature. An unauthenticated attacker can send crafted HTTP or HTTPS POST requests to the /ibe endpoint containing path traversal sequences (e.g., ../) combined with NULL byte injection to bypass input validation, enabling arbitrary file writes to any location on the underlying system. No authentication or user interaction is required, and the attack is fully automatable over the network. The vulnerability was internally discovered and reported by Gwendal Guégniaud of Fortinet's Product Security team (FortiGuard Advisory, GitHub Advisory).

영향

Successful exploitation allows an unauthenticated attacker to write arbitrary files anywhere on the FortiMail system, which can lead to remote code execution, persistent backdoor installation, configuration tampering, and full system compromise. The combination of arbitrary file write and potential code execution means attackers can achieve complete confidentiality, integrity, and availability impact on the affected appliance. Given FortiMail's role as an email security gateway, compromise could expose sensitive email communications, enable lateral movement into internal networks, and facilitate further attacks on connected infrastructure. The vulnerability has been observed being used to install backdoors and establish persistent access (FortiGuard Advisory, CISA KEV, BleepingComputer).

악용 가능성

CVE-2026-104286 was exploited as a zero-day before patches were available and was added to CISA's KEV catalog on October 1, 2026, with a federal agency remediation deadline of October 4, 2026. Active exploitation has been confirmed and reported by multiple sources including watchTowr and BleepingComputer, with attackers observed writing files and establishing backdoors on FortiMail systems. A fake PoC repository (ShadowForge-Cyber/CVE-2026-104286-POC) was identified on GitHub but assessed as a fraudulent claim with no actual exploit code present. The EPSS score is approximately 2.2% (82nd percentile), and NVD SSVC classifies exploitation as active and automatable with total technical impact (CISA KEV, watchTowr, BleepingComputer, GitHub Advisory).

착취 단계

  1. Reconnaissance: Identify internet-facing FortiMail instances using tools like Shodan or Censys, targeting versions 7.0.x–7.6.x and 8.0.x. Confirm the IBE (Identity-Based Encryption) feature is enabled by probing the /ibe endpoint.
  2. Craft malicious HTTP request: Construct a POST request to the FortiMail /ibe endpoint with a path traversal payload in the filename or path parameter, combining ../ sequences with NULL byte injection (e.g., %00) to bypass server-side path restriction checks.
  3. Write arbitrary file: The crafted request causes FortiMail to write attacker-controlled content to an arbitrary location on the filesystem outside the intended restricted directory — for example, writing a web shell to a web-accessible directory or a cron job to /etc/cron.d/.
  4. Achieve code execution: Trigger the written payload (e.g., access the dropped web shell via HTTP, or wait for the cron job to execute) to gain remote code execution as the FortiMail service account.
  5. Establish persistence: Install a backdoor, exfiltrate credentials or email data, or pivot to internal network resources reachable from the FortiMail appliance (FortiGuard Advisory, watchTowr, BleepingComputer).

타협의 징후

  • Network: Inbound POST requests to /ibe endpoints containing ../ path traversal sequences or NULL bytes (%00); outbound connections from the FortiMail server to suspicious external IPs, particularly 79[.]141.169.187 and 45[.]129.0.192.
  • Logs (System Event): type=event subtype=system pri=debug user=system ui=cron msg="(root) CMD (/bin/sh -c 'O=/migadmin ..." indicating unauthorized cron execution; admin logout events from null UI sessions: type=kevent subtype=admin ... action=logout status=success reason=unknown msg="User admin logged out from (null)." ; configuration changes adding remote archive accounts pointing to attacker-controlled IPs: type=kevent subtype=config ... msg="Added 'archive234' to 'archive account' ... remote-ip[79.141.169.187]".
  • Logs (Encryption): FortiMail::IBE::DecrypterMediaIn::DecrypterMediaIn(...): Caught BufferException(2), BufferImpl.cpp:973, 'Invalid Base64 Encoding at pos 0. Character=0x2a'; failed internal user login attempts: Internal user *@domain.tld failed to log in.
  • File System: Unexpected files written outside normal FortiMail directories; new or modified cron jobs; web shells in web-accessible paths.
  • Process: Unusual child processes spawned by FortiMail service (e.g., /bin/sh, curl, wget) (FortiGuard Advisory).

완화 및 해결 방법

Fortinet released patches on October 5, 2026: upgrade to FortiMail 8.0.2 or above, 7.6.7 or above, 7.4.9 or above, or migrate from 7.2.x to branch 7.4 or above. FortiMail Cloud was automatically updated to v7.6.7 GA or v8.0.2 GA on October 5, 2026, requiring no action from cloud customers. For organizations unable to patch immediately, Fortinet recommends the following workarounds: (1) disable the IBE feature via GUI (Encryption → IBE → IBE Service 'off') or CLI (config system encryption ibe / set status disable / end); (2) restrict or disable access to the FortiMail webmail interface from the internet; (3) if a WAF is deployed in front of FortiMail, configure it to block POST requests to /ibe containing ../. CISA directed federal agencies to remediate by October 4, 2026 (FortiGuard Advisory, CISA KEV).

커뮤니티 반응

Fortinet issued an urgent advisory (FG-IR-26-175) on October 1, 2026, explicitly warning customers of active exploitation and urging immediate application of workarounds before patches were available. CISA added the vulnerability to its KEV catalog the same day with a 3-day remediation deadline for federal agencies, reflecting the severity of the threat. Security researchers at watchTowr published a detailed FAQ on the vulnerability, and multiple outlets including BleepingComputer, The Hacker News, SecurityWeek, and Help Net Security covered the zero-day extensively. Community discussion on Reddit (r/SecOpsDaily, r/linuxadmin) and social media platforms highlighted concerns about the lack of patches at initial disclosure and the exposure of internet-facing email gateways. The CIS, Canadian Centre for Cyber Security (CCCS), Hong Kong CERT, and Ireland NCSC all issued independent advisories (FortiGuard Advisory, BleepingComputer, watchTowr, CISA KEV).

추가 자료


근원: 이 보고서는 AI를 사용하여 생성되었습니다.

관련 Fortimail 취약점:

CVE ID

심각도

점수

기술

구성 요소 이름

CISA KEV 익스플로잇

수정 사항이 있습니다.

게시된 날짜

CVE-2026-104286CRITICAL9.8
  • Fortimail logoFortimail
  • cpe:2.3:a:fortinet:fortimail
예아니요Oct 01, 2026
CVE-2025-53681HIGH7.2
  • Fortimail logoFortimail
  • cpe:2.3:a:fortinet:fortimail
아니요예May 12, 2026
CVE-2025-54972MEDIUM4.3
  • Fortimail logoFortimail
  • cpe:2.3:a:fortinet:fortimail
아니요예Nov 18, 2025
CVE-2024-47569MEDIUM4.3
  • FortiOS logoFortiOS
  • cpe:2.3:o:fortinet:fortios
아니요예Oct 14, 2025
CVE-2025-55717MEDIUM4
  • Fortimail logoFortimail
  • cpe:2.3:a:fortinet:fortimail
아니요예Mar 10, 2026

무료 취약성 평가

클라우드 보안 태세를 벤치마킹합니다

9개의 보안 도메인에서 클라우드 보안 관행을 평가하여 위험 수준을 벤치마킹하고 방어의 허점을 식별합니다.

평가 요청

추가 Wiz 리소스

맞춤형 데모 받기

맞춤형 데모 신청하기

"내가 본 최고의 사용자 경험은 클라우드 워크로드에 대한 완전한 가시성을 제공합니다."
데이비드 에슬릭최고정보책임자(CISO)
"Wiz는 클라우드 환경에서 무슨 일이 일어나고 있는지 볼 수 있는 단일 창을 제공합니다."
아담 플레처최고 보안 책임자(CSO)
"우리는 Wiz가 무언가를 중요한 것으로 식별하면 실제로 중요하다는 것을 알고 있습니다."
그렉 포니아토프스키위협 및 취약성 관리 책임자