CVE-2026-49217

Source
https://cve.org/CVERecord?id=CVE-2026-49217
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-49217.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-49217
Aliases
  • GHSA-2w8v-6xr5-g9gh
Published
2026-08-20T22:01:41Z
Modified
2026-09-20T11:31:04Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
Mailu missing authentication on PATCH /api/v1/token/<id>, which allows unauthenticated removal of IP restrictions
Details

Mailu is a mail server as a set of Docker images. Prior to version 2024.06.52, a missing authorization check in the Mailu admin REST API allows any unauthenticated attacker to remove any potential IP restriction or update the comment field from any existing user token provided the REST API is enabled. Upgrade to Mailu 2024.06.52 to receive a patch or, as a workaround, turn the REST API off.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-306"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/49xxx/CVE-2026-49217.json"
}
References

Affected packages

Git / github.com/mailu/mailu

Affected ranges

Type
GIT
Repo
https://github.com/mailu/mailu
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2024.06.52"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

1.*
1.8-rc
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.*
2.0.0
2024.*
2024.06.0
2024.06.1
2024.06.10
2024.06.11
2024.06.12
2024.06.13
2024.06.14
2024.06.15
2024.06.16
2024.06.17
2024.06.18
2024.06.19
2024.06.2
2024.06.20
2024.06.21
2024.06.22
2024.06.23
2024.06.24
2024.06.25
2024.06.26
2024.06.27
2024.06.28
2024.06.29
2024.06.3
2024.06.30
2024.06.31
2024.06.32
2024.06.33
2024.06.34
2024.06.35
2024.06.36
2024.06.37
2024.06.38
2024.06.39
2024.06.4
2024.06.40
2024.06.41
2024.06.42
2024.06.43
2024.06.44
2024.06.45
2024.06.46
2024.06.47
2024.06.48
2024.06.49
2024.06.5
2024.06.50
2024.06.51
2024.06.6
2024.06.7
2024.06.8
2024.06.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-49217.json"