Multiple Cross-Site Scripting (XSS) Vulnerabilities in Mailcow
ID: 64f98a25-9970-5d5e-915f-d7300a8b7e72
STIX ID: report--64f98a25-9970-5d5e-915f-d7300a8b7e72
Feed Name: Aikido Security's Blog
Threat Score
Mailcow was found vulnerable to three stored XSS issues (CVE-2026-40872, CVE-2026-40873, CVE-2026-40875) that allowed unauthenticated injection via Autodiscover logs, quarantined attachment filenames, and an unescaped login-history IP field; combined with a Login CSRF this could enable admin account takeover and mailbox exfiltration. All issues were responsibly disclosed and patched in Mailcow version 2026-03b (released March 31, 2026).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
