Directory Traversal Vulnerability in Exim Mail Transfer Agent
CVE-2026-66140

8.4HIGH

Key Information:

Vendor

Exim

Status
Vendor
CVE Published:
24 July 2026

What is CVE-2026-66140?

Exim Mail Transfer Agent versions prior to 4.99.5 are susceptible to a directory traversal vulnerability that allows attackers to access files located outside of the intended spool area. This is achieved through the mishandling of queue-name arguments, which can lead to unintended file access and privilege escalation. Organizations using affected versions are advised to upgrade to the latest release to mitigate this risk.

Affected Version(s)

Exim 4.88 < 4.99.5

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.