CyberRota Analysis
AI-GeneratedExim versions prior to 4.99.5 are vulnerable to a privilege escalation attack due to improper handling of the force_command option for pipe transport in .forward files. This flaw could allow an attacker to execute arbitrary commands with elevated privileges, potentially compromising the mail server's integrity. Organizations using affected Exim versions should prioritize patching to mitigate the risk of exploitation.
CVE
CVE-2026-66141
Severity
HIGH
CVSS
7.4
EPSS
0.10%
Original NVD Description
Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.
Related CVEs
Other vulnerabilities affecting the same vendor(s)