Detect Fortinet FortiMail Path Traversal Exploitation (CVE-2026-104286) in Elastic Security
Detects exploitation attempts against CVE-2026-104286, a path traversal vulnerability (CWE-22 / CWE-158) in Fortinet FortiMail that is actively exploited in the wild (CISA KEV). Attackers leverage directory traversal sequences and improper handling of null/escape characters in HTTP requests to the FortiMail administrative and webmail interfaces to read arbitrary files, access configuration, or achieve code execution. This detection identifies traversal payloads (../, encoded variants, null-byte truncation) in requests to FortiMail management endpoints, anomalous file access, and post-exploitation indicators.
MITRE ATT&CK
Elastic Detection Query
network where event.category == "network" and
(url.original : "*../*" or url.original : "*..%2f*" or url.original : "*%2e%2e%2f*" or url.original : "*..%5c*" or url.original : "*%00*" or url.original : "*....//*") and
(url.path : "*/admin*" or url.path : "*/api*" or url.path : "*/webmail*" or url.path : "*/cgi-bin*" or url.path : "*/download*") and
observer.vendor : "Fortinet" EQL rule matching FortiMail HTTP requests with traversal/null-byte sequences on sensitive paths.
Data Sources
Required Tables
False Positives & Tuning
- Authorized scanning infrastructure
- Penetration testing windows
- Benign webmail download URLs with encoded parameters
Other platforms for CVE-2026-104286
Testing Methodology
Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.
- Test 1Basic path traversal against FortiMail download endpoint
Expected signal: FortiMail HTTP access log entry with RequestURL containing '../../../../etc/passwd' to /download.
- Test 2URL-encoded traversal against admin API
Expected signal: FortiMail/web proxy log with encoded %2e%2e%2f sequence against /api path.
- Test 3Null-byte truncation traversal (CWE-158)
Expected signal: Web/proxy log capturing %00 null-byte plus traversal sequence to /webmail.
References (5)
- https://fortiguard.fortinet.com/psirt/FG-IR-26-175
- https://nvd.nist.gov/vuln/detail/CVE-2026-104286
- https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk
- https://www.bleepingcomputer.com/news/security/fortinet-warns-of-critical-fortimail-flaw-exploited-in-zero-day-attacks/
Response Playbook
Triage
- Confirm the targeted appliance is FortiMail and identify its firmware version against FG-IR-26-175 to determine exploitability.
- Extract the full request URL(s) and decode traversal/null-byte sequences to determine which file paths the attacker attempted to access (e.g. /etc/passwd, FortiMail config, session files).
- Determine whether the request received a 200/successful response versus being blocked (4xx) to distinguish successful reads from blocked attempts.
- Check the source IP reputation and cross-reference against CISA KEV / threat-intel feeds for known CVE-2026-104286 exploitation infrastructure.
Containment
- Block the attacker source IP(s) at the perimeter firewall and on the FortiMail trusted-host/admin access list.
- Restrict FortiMail administrative and API interface exposure to management networks only; remove any internet-facing exposure of the admin GUI.
- Apply the Fortinet FG-IR-26-175 patched firmware or vendor-provided workaround immediately given active KEV exploitation.
Evidence Collection
- Export FortiMail HTTP/admin access logs, system event logs, and any available full packet captures covering the attack window.
- Capture the current FortiMail configuration backup and hashes of system binaries to detect tampering or implanted webshells.
Escalation Criteria
- !Escalate to incident response if any traversal request returned a successful (2xx) response indicating confirmed file disclosure.
- !Escalate immediately if post-exploitation indicators are present (new admin accounts, config changes, outbound C2, modified system files).
Investigation Guide
Related Techniques
Forensic Artifacts
- >
FortiMail HTTP/admin access logs showing traversal request URLs and response codes - >
FortiMail configuration backup diffs and system event logs - >
Network flow / PCAP records of connections from the source IP to the appliance management port
Tuning Guidance
Baseline and allowlist authorized vulnerability scanners and penetration-testing source IPs. Tighten the path filter to the specific vulnerable FortiMail endpoints identified in FG-IR-26-175 once published to reduce benign webmail download noise. Where available, correlate with HTTP response codes and only alert on 2xx responses to confirmed traversal to cut false positives, while keeping a lower-severity rule for blocked attempts.
Hunting Queries
Surfaces source IPs issuing repeated traversal/null-byte requests against FortiMail over time to spot scanning and exploitation bursts.
CommonSecurityLog | where DeviceVendor == "Fortinet" and DeviceProduct has "FortiMail" | where RequestURL has_any ("%00","../","..%2f","....//") | summarize count() by SourceIP, bin(TimeGenerated, 1h) index=fortinet sourcetype="fortinet:fortimail" (uri="*../*" OR uri="*%00*" OR uri="*....//*") | stats count by src_ip, uri Atomic Red Team Tests
Simulates a directory traversal attempt to read /etc/passwd via the FortiMail web interface in a lab.
Command
curl -ks "https://fortimail.lab.local/download?file=../../../../etc/passwd" -o /tmp/cve_2026_104286_test.out Cleanup
rm -f /tmp/cve_2026_104286_test.out Expected Telemetry
FortiMail HTTP access log entry with RequestURL containing '../../../../etc/passwd' to /download.
Expected Detection
Detection fires on the '../' traversal sequence targeting the /download path.
Sends a URL-encoded traversal payload to the FortiMail admin API endpoint.
Command
curl -ks "https://fortimail.lab.local/api/v1/file?path=%2e%2e%2f%2e%2e%2f%2e%2e%2fconfig" -o /dev/null Cleanup
echo 'no cleanup required' Expected Telemetry
FortiMail/web proxy log with encoded %2e%2e%2f sequence against /api path.
Expected Detection
Detection matches the %2e%2e%2f encoded traversal pattern on the /api endpoint.
Tests null-byte injection combined with traversal against the webmail endpoint.
Command
powershell -Command "Invoke-WebRequest -Uri 'https://fortimail.lab.local/webmail?attach=..%2f..%2fetc%2fpasswd%00.png' -SkipCertificateCheck -OutFile $env:TEMP\cve104286.out" Cleanup
powershell -Command "Remove-Item $env:TEMP\cve104286.out -ErrorAction SilentlyContinue" Expected Telemetry
Web/proxy log capturing %00 null-byte plus traversal sequence to /webmail.
Expected Detection
Detection fires on the %00 null-byte and traversal pattern on the /webmail path.