An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability...

zetlyn/cve-ghsa vulnerability ghsa GHSA-6gxc-3vv7-7w24 cve CVE-2026-104286 known 2026-10-01

https://github.com/advisories/GHSA-6gxc-3vv7-7w24

Properties

cvss9.8
receipt
Source
GitHub advisories
Its words
9.8
Read by
field:cvss.score
Said since
2026-10-02 11:59 UTC
Last answered
2026-10-05 12:22 UTC
Original
open at the source
What the source handed over
{
  "credits": [],
  "cve_id": "CVE-2026-104286",
  "cvss": {
    "score": 9.8,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 9.8,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
    },
    "cvss_v4": {
      "score": 0.0,
      "vector_string": null
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-22",
      "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"
    }
  ],
  "description": "An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.",
  "ghsa_id": "GHSA-6gxc-3vv7-7w24",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-6gxc-3vv7-7w24",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-6gxc-3vv7-7w24"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-104286"
    }
  ],
  "nvd_published_at": "2026-10-01T20:17:24Z",
  "published_at": "2026-10-01T21:32:52Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-104286",
    "https://fortiguard.fortinet.com/psirt/FG-IR-26-175",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-104286",
    "https://github.com/advisories/GHSA-6gxc-3vv7-7w24"
  ],
  "repository_advisory_url": null,
  "severity": "critical",
  "source_code_location": "",
  "summary": "An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability...",
  "type": "unreviewed",
  "updated_at": "2026-10-01T21:33:02Z",
  "url": "https://api.github.com/advisories/GHSA-6gxc-3vv7-7w24",
  "vulnerabilities": [],
  "withdrawn_at": null
}
cweCWE-22
receipt
Source
GitHub advisories
Its words
CWE-22
Read by
field:cwes[].cwe_id
Said since
2026-10-02 11:59 UTC
Last answered
2026-10-05 12:22 UTC
Original
open at the source
What the source handed over
{
  "credits": [],
  "cve_id": "CVE-2026-104286",
  "cvss": {
    "score": 9.8,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 9.8,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
    },
    "cvss_v4": {
      "score": 0.0,
      "vector_string": null
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-22",
      "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"
    }
  ],
  "description": "An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.",
  "ghsa_id": "GHSA-6gxc-3vv7-7w24",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-6gxc-3vv7-7w24",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-6gxc-3vv7-7w24"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-104286"
    }
  ],
  "nvd_published_at": "2026-10-01T20:17:24Z",
  "published_at": "2026-10-01T21:32:52Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-104286",
    "https://fortiguard.fortinet.com/psirt/FG-IR-26-175",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-104286",
    "https://github.com/advisories/GHSA-6gxc-3vv7-7w24"
  ],
  "repository_advisory_url": null,
  "severity": "critical",
  "source_code_location": "",
  "summary": "An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability...",
  "type": "unreviewed",
  "updated_at": "2026-10-01T21:33:02Z",
  "url": "https://api.github.com/advisories/GHSA-6gxc-3vv7-7w24",
  "vulnerabilities": [],
  "withdrawn_at": null
}
severitycritical
GitHub's own rating, from the CVSS base score at 9.0 and above.
receipt
Source
GitHub advisories
Its words
critical
Read by
field:severity
Said since
2026-10-02 11:59 UTC
Last answered
2026-10-05 12:22 UTC
Original
open at the source
What the source handed over
{
  "credits": [],
  "cve_id": "CVE-2026-104286",
  "cvss": {
    "score": 9.8,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 9.8,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
    },
    "cvss_v4": {
      "score": 0.0,
      "vector_string": null
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-22",
      "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"
    }
  ],
  "description": "An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.",
  "ghsa_id": "GHSA-6gxc-3vv7-7w24",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-6gxc-3vv7-7w24",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-6gxc-3vv7-7w24"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-104286"
    }
  ],
  "nvd_published_at": "2026-10-01T20:17:24Z",
  "published_at": "2026-10-01T21:32:52Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-104286",
    "https://fortiguard.fortinet.com/psirt/FG-IR-26-175",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-104286",
    "https://github.com/advisories/GHSA-6gxc-3vv7-7w24"
  ],
  "repository_advisory_url": null,
  "severity": "critical",
  "source_code_location": "",
  "summary": "An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability...",
  "type": "unreviewed",
  "updated_at": "2026-10-01T21:33:02Z",
  "url": "https://api.github.com/advisories/GHSA-6gxc-3vv7-7w24",
  "vulnerabilities": [],
  "withdrawn_at": null
}

Text

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability... An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.