CVE-2026-40871Disclosure

LOWCVSS 7.2 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

mailcow: dockerized is an open source groupware/email suite based on docker. Versions prior to 2026-03b have a second-order SQL injection vulnerability in the quarantine_category field via the Mailcow API. The /api/v1/add/mailbox endpoint stores quarantine_category without validation or sanitization. This value is later used by quarantine_notify.py, which constructs SQL queries using unsafe % string formatting instead of parameterized queries. This results in a delayed (second-order) SQL injection when the quarantine notification job executes, allowing an attacker to inject arbitrary SQL. Using a UNION SELECT, sensitive data (e.g., admin credentials) can be exfiltrated and rendered inside quarantine notification emails. Version 2026-03b fixes the vulnerability.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-89CWE-116CWE-564

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 2 mentions (2026-04-20); latest day: 1
  • 5 total mentions across 4 days

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-04-19: 1Mentions · 2026-04-20: 2Mentions · 2026-04-22: 1Mentions · 2026-04-27: 1PoC Mentioned / Linked · 2026-04-19: 1PoC Mentioned / Linked · 2026-04-20: 2Exploit Tool / Code · 2026-04-20: 1Technical Details · 2026-04-19: 1Technical Details · 2026-04-20: 2Technical Details · 2026-04-22: 1Technical Details · 2026-04-27: 104-1904-2004-2204-27
Signal classification1 categories
Disclosure
5100.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-191
Disclosure1
2026-04-202
Disclosure2
2026-04-221
Disclosure1
2026-04-271
Disclosure1
Full discourse5 posts
  • NullSecurityX@NullSecurityX
    Disclosure

    CVE-2026-40871 Second-Order SQL Injection / Sensitive Data Exposure Affected Component: Mailcow API (/api/v1/add/mailbox) + quarantine_notify.py Details: https://github.com/lukehebe/Vulnerability-Disclosures/blob/main/CVE-2026-40871.md https://t.co/BFGWHCk5oe

    Post summary

    The tweet announces CVE-2026-40871, a second‑order SQL injection that exposes sensitive data in the Mailcow API, and directs readers to a GitHub disclosure for further details.

    22712048911.3K
    12.3K followersView on X
  • Nicolas Krassas@Dinosn
    Disclosure

    Found and reported a Second-Order SQL Injection in mailcow (CVE-2026-40871) – High severity https://github.com/lukehebe/Vulnerability-Disclosures/blob/main/CVE-2026-40871.md

    Post summary

    A high‑severity second‑order SQL injection in Mailcow (CVE‑2026‑40871) was identified and publicly disclosed, with details available on a GitHub repository.

    2160119678.0K
    158.1K followersView on X
  • N45HT@N45HTOfficial
    Disclosure

    CVE-2026-40871 💥 Second-Order SQL Injection via quarantine_category in Mailcow by lukehebe 🤯🔥 👨‍💻 lhebs (gh/lukehebe) 🔗 https://github.com/lukehebe/Vulnerability-Disclosures/blob/main/CVE-2026-40871.md 🔗 https://t.me/ZeroToBug 🔗 https://whatsapp.com/channel/0029VbCTM6RDp2QAFE8r140p https://t.co/Q2gLwcPJQH

    Post summary

    The tweet announces CVE‑2026‑40871, a second‑order SQL injection in Mailcow, and shares a link to a detailed disclosure (including PoC code) on GitHub, with no indication of active exploitation or remediation.

    0001049
    70 followersView on X
  • CompuChris@compuchris
    Disclosure

    Found and reported a Second-Order SQL Injection in mailcow (CVE-2026-40871) – High severity #CISO https://www.reddit.com/r/cybersecurity/comments/1spvqrv/found_and_reported_a_secondorder_sql_injection_in/

    Post summary

    A new high‑severity second‑order SQL injection (CVE‑2026‑40871) has been discovered and reported in mailcow.

    0000039
    1.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40871 Second-Order SQL Injection in mailcow Dockerized Prior to Version 2026-0... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40871 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The post announces CVE-2026-40871 as a second‑order SQL injection in mailcow Dockerized before version 2026‑0, but provides neither PoC nor exploit details, active exploitation evidence, or patch information.

    0000040
    4.0K followersView on X

Explore more