« Volver al listado

CVE-2026-85751

Estado: AplazadaCrítica (9.8)—

Mailu is a mail server distributed as a set of Docker images. From Mailu 2.0 until 2024.06.55 and prior to Mailu helm-charts 2.7.3, deployments with PROXY_AUTH_WHITELIST configured but REAL_IP_HEADER unset trusted a client-controlled X-Forwarded-By header for header-based proxy authentication. The proxy_hide_header directive in the nginx template at core/nginx/conf/proxy.conf hid the header from upstream responses but did not overwrite the incoming request value in this configuration. An unauthenticated remote attacker could therefore spoof the trusted proxy identity and bypass authentication. This issue is fixed in Mailu 2024.06.55 and Mailu helm-charts 2.7.3.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vector AV:N/PR:N sin UI indica T1190. Spoofing de X-Forwarded-By para bypassear autenticación (CWE-290) logra acceso no autorizado (T1078) y manipulación de autenticación (T1556).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (2)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-85751",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-85751",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-09-21T17:56:04.999383Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "Mailu",
          "product": "Mailu",
          "versions": [
            {
              "status": "affected",
              "version": ">= 2.0.0, < 2024.06.55"
            }
          ]
        },
        {
          "vendor": "Mailu",
          "product": "helm-charts",
          "versions": [
            {
              "status": "affected",
              "version": "< 2.7.3"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-09-21T16:17:25.070",
  "references": [
    {
      "url": "https://github.com/Mailu/Mailu/commit/dffa97cbd889ab208246372ce9c86e99abb27ae9",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/Mailu/Mailu/commit/ff4003d045753013470945336448dbd790cac778",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/Mailu/Mailu/pull/4070",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/Mailu/Mailu/pull/4071",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/Mailu/Mailu/releases/tag/2024.06.55",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/Mailu/Mailu/security/advisories/GHSA-rfhj-4wcq-74xg",
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-290"
        },
        {
          "lang": "en",
          "value": "CWE-807"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Mailu is a mail server distributed as a set of Docker images. From Mailu 2.0 until 2024.06.55 and prior to Mailu helm-charts 2.7.3, deployments with PROXY_AUTH_WHITELIST configured but REAL_IP_HEADER unset trusted a client-controlled X-Forwarded-By header for header-based proxy authentication. The proxy_hide_header directive in the nginx template at core/nginx/conf/proxy.conf hid the header from upstream responses but did not overwrite the incoming request value in this configuration. An unauthenticated remote attacker could therefore spoof the trusted proxy identity and bypass authentication. This issue is fixed in Mailu 2024.06.55 and Mailu helm-charts 2.7.3."
    }
  ],
  "lastModified": "2026-09-24T21:25:27.050",
  "sourceIdentifier": "security-advisories@github.com"
}