CVE-2026-104286 Google Chronicle · YARA-L

Detect Fortinet FortiMail Path Traversal Exploitation (CVE-2026-104286) in Google Chronicle

Detects exploitation attempts against CVE-2026-104286, a path traversal vulnerability (CWE-22 / CWE-158) in Fortinet FortiMail that is actively exploited in the wild (CISA KEV). Attackers leverage directory traversal sequences and improper handling of null/escape characters in HTTP requests to the FortiMail administrative and webmail interfaces to read arbitrary files, access configuration, or achieve code execution. This detection identifies traversal payloads (../, encoded variants, null-byte truncation) in requests to FortiMail management endpoints, anomalous file access, and post-exploitation indicators.

MITRE ATT&CK

Tactic
Initial Access Collection Defense Evasion

YARA-L Detection Query

Google Chronicle (YARA-L)
yaral
rule fortimail_cve_2026_104286_path_traversal {
  meta:
    author = "Argus"
    description = "FortiMail path traversal exploitation CVE-2026-104286"
    severity = "CRITICAL"
  events:
    $e.metadata.vendor_name = /Fortinet/ nocase
    $e.target.application = /FortiMail/ nocase
    (
      re.regex($e.network.http.referral_url, `\.\./|\.\.%2f|%2e%2e%2f|\.\.%5c|%00|\.\.\.\.//`) nocase or
      re.regex($e.target.url, `\.\./|\.\.%2f|%2e%2e%2f|\.\.%5c|%00|\.\.\.\.//`) nocase
    )
    re.regex($e.target.url, `/admin|/api|/webmail|/cgi-bin|/download`) nocase
    $src = $e.principal.ip
  match:
    $src over 10m
  condition:
    $e
}
critical severity medium confidence

Chronicle YARA-L rule detecting traversal payloads to FortiMail URLs.

Data Sources

Fortinet UDMWeb ProxyNetwork

Required Tables

udm.events

False Positives & Tuning

  • Authorized vulnerability scanning
  • Security testing engagements
  • Benign encoded webmail URLs

Other platforms for CVE-2026-104286


Testing Methodology

Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.

  1. Test 1Basic path traversal against FortiMail download endpoint

    Expected signal: FortiMail HTTP access log entry with RequestURL containing '../../../../etc/passwd' to /download.

  2. Test 2URL-encoded traversal against admin API

    Expected signal: FortiMail/web proxy log with encoded %2e%2e%2f sequence against /api path.

  3. Test 3Null-byte truncation traversal (CWE-158)

    Expected signal: Web/proxy log capturing %00 null-byte plus traversal sequence to /webmail.


Response Playbook

Triage

  1. Confirm the targeted appliance is FortiMail and identify its firmware version against FG-IR-26-175 to determine exploitability.
  2. Extract the full request URL(s) and decode traversal/null-byte sequences to determine which file paths the attacker attempted to access (e.g. /etc/passwd, FortiMail config, session files).
  3. Determine whether the request received a 200/successful response versus being blocked (4xx) to distinguish successful reads from blocked attempts.
  4. Check the source IP reputation and cross-reference against CISA KEV / threat-intel feeds for known CVE-2026-104286 exploitation infrastructure.

Containment

  1. Block the attacker source IP(s) at the perimeter firewall and on the FortiMail trusted-host/admin access list.
  2. Restrict FortiMail administrative and API interface exposure to management networks only; remove any internet-facing exposure of the admin GUI.
  3. Apply the Fortinet FG-IR-26-175 patched firmware or vendor-provided workaround immediately given active KEV exploitation.

Evidence Collection

  1. Export FortiMail HTTP/admin access logs, system event logs, and any available full packet captures covering the attack window.
  2. Capture the current FortiMail configuration backup and hashes of system binaries to detect tampering or implanted webshells.

Escalation Criteria

  • !Escalate to incident response if any traversal request returned a successful (2xx) response indicating confirmed file disclosure.
  • !Escalate immediately if post-exploitation indicators are present (new admin accounts, config changes, outbound C2, modified system files).

Investigation Guide

Related Techniques

Forensic Artifacts

  • >FortiMail HTTP/admin access logs showing traversal request URLs and response codes
  • >FortiMail configuration backup diffs and system event logs
  • >Network flow / PCAP records of connections from the source IP to the appliance management port

Tuning Guidance

Baseline and allowlist authorized vulnerability scanners and penetration-testing source IPs. Tighten the path filter to the specific vulnerable FortiMail endpoints identified in FG-IR-26-175 once published to reduce benign webmail download noise. Where available, correlate with HTTP response codes and only alert on 2xx responses to confirmed traversal to cut false positives, while keeping a lower-severity rule for blocked attempts.


Hunting Queries

Surfaces source IPs issuing repeated traversal/null-byte requests against FortiMail over time to spot scanning and exploitation bursts.

Hunting — KQL
kql
CommonSecurityLog | where DeviceVendor == "Fortinet" and DeviceProduct has "FortiMail" | where RequestURL has_any ("%00","../","..%2f","....//") | summarize count() by SourceIP, bin(TimeGenerated, 1h)
Hunting — SPL
spl
index=fortinet sourcetype="fortinet:fortimail" (uri="*../*" OR uri="*%00*" OR uri="*....//*") | stats count by src_ip, uri

Atomic Red Team Tests

Test 1 Basic path traversal against FortiMail download endpoint
linux

Simulates a directory traversal attempt to read /etc/passwd via the FortiMail web interface in a lab.

Command

bash
curl -ks "https://fortimail.lab.local/download?file=../../../../etc/passwd" -o /tmp/cve_2026_104286_test.out

Cleanup

bash
rm -f /tmp/cve_2026_104286_test.out

Expected Telemetry

FortiMail HTTP access log entry with RequestURL containing '../../../../etc/passwd' to /download.

Expected Detection

Detection fires on the '../' traversal sequence targeting the /download path.

Test 2 URL-encoded traversal against admin API
linux

Sends a URL-encoded traversal payload to the FortiMail admin API endpoint.

Command

bash
curl -ks "https://fortimail.lab.local/api/v1/file?path=%2e%2e%2f%2e%2e%2f%2e%2e%2fconfig" -o /dev/null

Cleanup

bash
echo 'no cleanup required'

Expected Telemetry

FortiMail/web proxy log with encoded %2e%2e%2f sequence against /api path.

Expected Detection

Detection matches the %2e%2e%2f encoded traversal pattern on the /api endpoint.

Test 3 Null-byte truncation traversal (CWE-158)
windows

Tests null-byte injection combined with traversal against the webmail endpoint.

Command

powershell
powershell -Command "Invoke-WebRequest -Uri 'https://fortimail.lab.local/webmail?attach=..%2f..%2fetc%2fpasswd%00.png' -SkipCertificateCheck -OutFile $env:TEMP\cve104286.out"

Cleanup

powershell
powershell -Command "Remove-Item $env:TEMP\cve104286.out -ErrorAction SilentlyContinue"

Expected Telemetry

Web/proxy log capturing %00 null-byte plus traversal sequence to /webmail.

Expected Detection

Detection fires on the %00 null-byte and traversal pattern on the /webmail path.

Related Detections