Cleartext Credential Storage Vulnerability in MailEnable
CVE-2025-34427
What is CVE-2025-34427?
MailEnable versions prior to 10.54 are susceptible to a vulnerability that involves the storage of user and administrative credentials in plaintext format within the AUTH.TAB file. This misconfiguration allows local authenticated users with read access to gain unauthorized access to user passwords and super-admin credentials. Consequently, these credentials can be exploited to access MailEnable services such as POP3, SMTP, and the webmail interface, resulting in potential account takeover and unauthorized administrative control over mailboxes.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
MailEnable 0 < 10.54
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
