CVE-2025-68722Disclosure(axigen / axigen_mail_server)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Axigen Mail Server before 10.5.57 and 10.6.x before 10.6.26 contains a Cross-Site Request Forgery (CSRF) vulnerability in the WebAdmin interface through improper handling of the _s (breadcrumb) parameter. The application accepts state-changing requests via the GET method and automatically processes base64-encoded commands queued in the _s parameter immediately after administrator authentication. Attackers can craft malicious URLs that, when clicked by administrators, execute arbitrary administrative actions upon login without further user interaction, including creating rogue administrator accounts or modifying critical server configurations.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-352

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • axigen_mail_server

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
axigen_mail_server

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-05: 2Technical Details · 2026-02-05: 202-05
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2025-68722 Axigen Mail Server before 10.5.57 and 10.6.x before 10.6.26 contains a Cross-Site Request Forgery (CSRF) vulnerability in the WebAdmin interface through improper hand… https://www.cve.org/CVERecord?id=CVE-2025-68722

    Post summary

    A CSRF vulnerability (CVE-2025-68722) impacts Axigen Mail Server versions before 10.5.57 and 10.6.x before 10.6.26, affecting the WebAdmin interface; no PoC, exploit, patch, or active exploitation details are provided.

    00010176
    56.5K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2025-68722 - High Axigen Mail Server before 10.5.57 and 10.6.x before 10.6.26 contains a Cross-Site Request Forgery (CSRF) vulnerability in the WebAdmin interface through improper handling of the _s (breadcrum... https://www.thehackerwire.com/vulnerability/CVE-2025-68722/ https://t.co/tTqLodgr6L

    Post summary

    A new CSRF vulnerability (CVE-2025-68722) affecting Axigen Mail Server versions before 10.5.57 and 10.6.x before 10.6.26 was disclosed, noting its potential impact but providing no exploit or patch details.

    0000049
    113 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appaxigenaxigen_mail_server---

Explore more