logo

Multiple Cross-Site Scripting (XSS) Vulnerabilities in Mailcow

ID: 64f98a25-9970-5d5e-915f-d7300a8b7e72

STIX ID: report--64f98a25-9970-5d5e-915f-d7300a8b7e72

Feed Name: Aikido Security's Blog

Threat Score
75/100

Date Published: 2026-04-17

Date Updated: 2026-07-24

...
...

Mailcow was found vulnerable to three stored XSS issues (CVE-2026-40872, CVE-2026-40873, CVE-2026-40875) that allowed unauthenticated injection via Autodiscover logs, quarantined attachment filenames, and an unescaped login-history IP field; combined with a Login CSRF this could enable admin account takeover and mailbox exfiltration. All issues were responsibly disclosed and patched in Mailcow version 2026-03b (released March 31, 2026).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.