CVE-2026-40872Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the admin dashboard's Autodiscover logs render the EMailAddress value (logged as the "user" field) without HTML escaping. By submitting an unauthenticated Autodiscover request with a crafted EMailAddress containing HTML/JS, the payload is stored in Redis and executed when an admin views the Autodiscover logs. Version 2026-03b fixes the vulnerability.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-80

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-21); latest day: 2
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-04-21: 2Mentions · 2026-04-22: 2Patch / Workaround · 2026-04-22: 1Technical Details · 2026-04-21: 2Technical Details · 2026-04-22: 204-2104-22
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-212
Disclosure2
2026-04-222
Disclosure1Patch1
Full discourse4 posts
  • Autumn Good@autumn_good_35
    Disclosure

    🚨🚨🚨 CVE-2026-40872 Stored XSS in autodiscover logs email address field · Advisory · mailcow/mailcow-dockerized · GitHub https://github.com/mailcow/mailcow-dockerized/security/advisories/GHSA-f9xf-vc72-rcgm

    Post summary

    The tweet announces the CVE‑2026‑40872 vulnerability—a stored XSS in mailcow’s autodiscover logs—and provides a link to the GitHub advisory. No PoC, exploit code, or active exploitation details are mentioned.

    00031524
    6.9K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: CVE-2026-40872 A critical Stored XSS vulnerability in Mailcow was fixed! More info: https://github.com/mailcow/mailcow-dockerized/security/advisories/GHSA-f9xf-vc72-rcgm #Patch #Patch #Patch

    Post summary

    The alert announces that CVE-2026-40872, a critical Stored XSS vulnerability in Mailcow, has been fixed and directs readers to the patch advisory.

    00000183
    7.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40872 Stored Cross-Site Scripting in mailcow Autodiscover Logs Prior to... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40872 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet announces the discovery of a stored XSS vulnerability (CVE‑2026‑40872) in mailcow Autodiscover logs, linking to a vulnerability details page.

    0000043
    4.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-40872: mailcow: dockerized vulnerable t... Unauthenticated XSS via Autodiscover EMailAddress field hits admin dashboards - zero interaction needed, just wait for ... https://zerodaysignal.com/vulnerability/CVE-2026-40872 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The article announces CVE‑2026‑40872, noting an unauthenticated XSS flaw in mailcow’s Dockerized environment that exploits the Autodiscover EMailAddress field and can affect admin dashboards with no user interaction.

    0000064
    218 followersView on X

Explore more