CVE-2026-67448Active Exploitation

LOWCVSS 6.5 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Mailpit is an email testing tool and API for developers. From 1.29.0 until 1.30.6, Mailpit's server/server.go origin middleware checks the raw RequestURI for the /api/ prefix while Go's ServeMux routes using the percent-decoded URL path, and server/websockets/client.go configures websocket.Upgrader.CheckOrigin to return true. A malicious website can request /%61pi/events, skip corsOriginAccessControl(), reach the /api/events WebSocket handler, and receive live message IDs, Message-Id values, sender and recipient fields, subjects, tags, and body snippets from an unauthenticated default Mailpit instance after the user visits the site. This is a regression of the earlier WebSocket origin protection and does not affect deployments protected by --ui-auth-file. This issue is fixed in version 1.30.6.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-177CWE-200CWE-346

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-21: 1Active Exploitation · 2026-08-21: 1Technical Details · 2026-08-21: 108-21
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
Full discourse1 post
  • NewNormal Security@NewScanTeam
    Active Exploitation

    NewNormal Security turns the last 24 hours of CVEs into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 21 Aug 2026 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 📦 Actively-exploited build of a self-hosted conferencing server — code execution and account takeover with no login (TrueConf CVE-2026-72530, CVE-2026-72529) 🔓 API guard that reads a different path than the router — a re-spelled URL skips it and hands over every message in a dev mail catcher, password resets included (Mailpit CVE-2026-67448) ⚡ CMS mis-reading PHP open tags in user-supplied content, exploited in the wild this month — unauthenticated code execution (SPIP CVE-2026-77647) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #RCE #CSO #REDTEAM

    Post summary

    The report lists multiple CVEs that are actively exploited or have seen wild attacks, but does not provide PoC, patch details, or exploit code.

    0001037
    5 followersView on X

Explore more