Improper limitation of a pathname to a restricted directory

🚨SEVERITY: CRITICAL — CVSS 9.8Security Advisory

TL;DR 📌

  • CVSSv3 Score: 9.8 An Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) [CWE-22] and Improper Neutralization of NULL Byte or NULL Character [CWE-158] vulnerability may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.This has been reported to be exploited in the wild,…
  • Highest CVSS: 9.8 (Critical).
  • Listed in CISA KEV (2026-10-01) — this is being exploited in the wild.
  • Check the advisory for fixed releases — remediation detail is in the vendor link below.
  • CVEs: CVE-2026-104286.

What it is

CVE-2026-104286 is a path traversal flaw (CWE-22) combined with improper handling of NULL byte characters (CWE-158) in a Fortinet product. The weakness allows crafted HTTP or HTTPS requests to escape the intended restricted directory and write arbitrary files onto the underlying filesystem.

The access path is unauthenticated: no credentials are required, and the attacker only needs network reach to the HTTP/HTTPS service that exposes the vulnerable component. The NULL-byte handling issue suggests the flaw may defeat extension or path-suffix checks that would otherwise block traversal attempts.

The outcome is arbitrary file write on the host. Depending on where the attacker can place files, this can be used to plant executable content, overwrite configuration, or otherwise alter the system outside its intended file boundaries — all without authentication.

Fortinet has confirmed this is being exploited in the wild, and it is listed in the CISA Known Exploited Vulnerabilities catalogue, added 2026-10-01. The advisory carries a CVSS score of 9.8 (Critical).

What to do

  • Treat this as actively exploited now: prioritise it above routine patch cycles.
  • Apply the workaround Fortinet has published in advisory FG-IR-26-175 immediately, pending a fixed release — the advisory should be consulted directly for the exact mitigation steps, as they are not restated here.
  • No fixed version is listed yet; check FG-IR-26-175 for updates and apply the patched release as soon as Fortinet publishes one.
  • Restrict exposure of the affected HTTP/HTTPS management or service interface to trusted networks only, until the workaround is in place and a fix is applied.
  • Review system and web logs for unexpected file writes or path traversal patterns (e.g. requests containing ../ sequences or embedded NULL bytes) as part of a compromise check.
  • Confirm your deployed version against Fortinet’s advisory, since affected and fixed version ranges are not stated in the summary provided here.

For leadership 🧭

Executive summary. A critical, unauthenticated flaw in a Fortinet product lets attackers write files anywhere on the device’s filesystem via ordinary web requests, and Fortinet has confirmed it is already being exploited. This needs the published workaround applied today, not scheduled into a normal patch window.

Why it matters:

  • No authentication is needed — anyone with network access to the device’s HTTP or HTTPS service can attempt the attack.
  • The NULL-byte handling flaw appears designed to slip past extension or suffix checks meant to stop path traversal, so standard filtering may not catch it.
  • Arbitrary file write on the underlying system can be used to plant executable content or overwrite configuration, giving an attacker a foothold beyond the web interface.
  • It is listed in the CISA Known Exploited Vulnerabilities catalogue, confirming active exploitation rather than theoretical risk.

Now / Next / Later:

  • Now: Apply the workaround published in Fortinet advisory FG-IR-26-175 immediately, and restrict access to the affected HTTP/HTTPS interface to trusted networks only.
  • Next: Check Fortinet’s advisory for a fixed release and schedule the upgrade as soon as one is published; in the meantime review web and system logs for path traversal patterns or unexpected file writes.
  • Later: Establish a standing rule to isolate management and service HTTP/HTTPS interfaces on Fortinet devices from general network exposure, so future path-traversal-class flaws can’t be reached without authentication.

Source