Privilege Escalation Flaw in Exim Mail Server from Exim Software
CVE-2026-66141

7.4HIGH

Key Information:

Vendor

Exim

Status
Vendor
CVE Published:
24 July 2026

What is CVE-2026-66141?

Exim, a widely-used mail transfer agent, allows privilege escalation due to mishandling of the force_command setting for pipe transports. This vulnerability can enable unauthorized users to potentially execute arbitrary commands with elevated privileges, compromising the security of the affected system. Administrators are advised to upgrade to Exim version 4.99.5 or newer to mitigate this risk.

Affected Version(s)

Exim 4.82 < 4.99.5

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.