logo

Mailcow Critical Alert: Unauthenticated XSS Threatens Admin Takeover

ID: 99f83f49-2a94-56ad-82f2-3c9e899f38f8

STIX ID: report--99f83f49-2a94-56ad-82f2-3c9e899f38f8

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical stored XSS in mailcow:dockerized (CVE-2026-40872, CVSS 9.3) allows unauthenticated POSTs to /Autodiscover/Autodiscover.xml to store crafted email-address values that are not HTML-escaped; when an administrator views the Autodiscover logs the payload executes in their session, enabling session hijack, mailbox access, lateral movement, and full takeover — upgrade to version 2026-03b, audit Autodiscover logs, and rotate admin credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.