logo

Exim Vulnerability Lets Attackers Access Files Outside the Mail Spool

ID: 11526372-c304-535f-89a3-d4b24e151282

STIX ID: report--11526372-c304-535f-89a3-d4b24e151282

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-07-23

Date Updated: 2026-07-23

Author: Divya

...
...

A high-severity directory traversal vulnerability in Exim (versions 4.88–4.99.4) allows local attackers to manipulate queue-related command-line arguments to access files outside the mail spool and potentially escalate privileges; Exim 4.99.5 fixes the issue by hardening argument validation and restricting queue options to privileged users, and administrators are strongly advised to patch immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.