CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-49217

highCVSS 7.5covered by 1 sourcefirst seen 2026-08-20
Mailu is a mail server as a set of Docker images. Prior to version 2024.06.52, a missing authorization check in the Mailu admin REST API allows any unauthenticated attacker to remove any potential IP restriction or update the comment field from any existing user token provided the REST API is enabled. Upgrade to Mailu 2024.06.52 to receive a patch or, as a workaround, turn the REST API off.

⚡ Watch CVE-2026-49217

Get an email if CVE-2026-49217 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-49217

CVE.org record

Embed the live status

CVE-2026-49217 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-49217 status](https://www.csirts.com/badge/CVE-2026-49217)](https://www.csirts.com/cve/CVE-2026-49217)