SMTP Smuggling Vulnerability in Exim Email Server
CVE-2026-94057

4MEDIUM

Key Information:

Vendor

Exim

Status
Vendor
CVE Published:
19 September 2026

What is CVE-2026-94057?

The Exim email server, specifically versions before 4.100.1, is susceptible to a vulnerability that allows for SMTP smuggling. This occurs when a received message does not align with any sent message due to manipulation of crafted data sent after a rejection during the DATA processing stage. This flaw can potentially allow an attacker to exploit the email server's processing mechanisms, leading to unauthorized actions or information disclosure.

Affected Version(s)

Exim 0 < 4.100.1

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.