← Terug naar overzicht

A missing authorization check in the Mailu admin REST API (prior to version 2024.06.52) allows unauthenticated attackers to remove IP restrictions or modify comment fields on existing user tokens. The vulnerability is exploitable without any authentication, provided the REST API feature is enabled. Mailu is a mail server solution distributed as a set of Docker images. The flaw could allow attackers to bypass IP-based access controls on user tokens, potentially escalating access. A patch is available in Mailu version 2024.06.52. As a workaround, administrators are advised to disable the REST API entirely. The vulnerability has been assigned CVE-2026-49217 and is tracked in the NVD as well as a GitHub Security Advisory.

Affected products

  • Mailu

Related CVE's

  • CVE-2026-49217

Categories

  • Email & Messaging
  • Identity & Access
  • Web Technologies