SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-66140

HIGH · CVSS 8.4 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-07-24 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

Exim versions prior to 4.99.5 are vulnerable to a directory traversal attack that allows unauthorized access to files outside the designated spool area, potentially leading to privilege escalation. This vulnerability arises from improper handling of queue-name arguments, which could be exploited by attackers to manipulate file access. Organizations using affected Exim versions should prioritize patching to mitigate the risk of unauthorized access and privilege escalation.

CVE
CVE-2026-66140
Severity
HIGH
CVSS
8.4
EPSS
0.26%

Original NVD Description

Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.

Related CVEs

Other vulnerabilities affecting the same vendor(s)