Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade exim | Jul 28, 2026 | Jul 24, 2026 |
| Debian | — | Upgrade exim4 | Jul 28, 2026 | Jul 28, 2026 |
| Exim | — | Upgrade Exim to version 4.99.5 | Aug 18, 2026 | Jul 24, 2026 |
| Ubuntu | — | Upgrade exim4 | Jul 29, 2026 | Jul 24, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub