Arbitrary Command Execution in Email::Sender::Transport::Sendmail for Perl on Windows
CVE-2026-93012

Currently unrated

Key Information:

Vendor

Perl

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-93012?

A vulnerability exists in Email::Sender::Transport::Sendmail for Perl prior to version 2.602 that allows attackers to execute arbitrary commands on Windows systems. This occurs when the envelope address is processed improperly, allowing control over the command string passed to the shell. Consequently, if an attacker can manipulate the 'To', 'Cc', or 'From' headers, they can execute commands with the privileges of the sending process, posing significant security risks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.