Email Personal Assistant Vulnerability in Inbox Zero by Elie222
CVE-2026-42865

2.3LOW

Key Information:

Vendor

Elie222

Vendor
CVE Published:
11 May 2026

What is CVE-2026-42865?

The Inbox Zero personal assistant for email, prior to version 2.29.3, was affected by a vulnerability wherein the cleaner email stream endpoint utilized a shared Redis subscription listener. This misconfiguration allowed thread events intended for one authenticated account to be inadvertently delivered to another authenticated account using the cleaner feature simultaneously, thereby compromising user privacy and security. The issue has been rectified in the latest version 2.29.3.

Affected Version(s)

inbox-zero < 2.29.3

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.