SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-66141

HIGH · CVSS 7.4 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-07-24 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

Exim versions prior to 4.99.5 are vulnerable to a privilege escalation attack due to improper handling of the force_command option for pipe transport in .forward files. This flaw could allow an attacker to execute arbitrary commands with elevated privileges, potentially compromising the mail server's integrity. Organizations using affected Exim versions should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-66141
Severity
HIGH
CVSS
7.4
EPSS
0.10%

Original NVD Description

Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.

Related CVEs

Other vulnerabilities affecting the same vendor(s)