CVE-2026-85751

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Mailu is a mail server distributed as a set of Docker images. From Mailu 2.0 until 2024.06.55 and prior to Mailu helm-charts 2.7.3, deployments with PROXY_AUTH_WHITELIST configured but REAL_IP_HEADER unset trusted a client-controlled X-Forwarded-By header for header-based proxy authentication. The proxy_hide_header directive in the nginx template at core/nginx/conf/proxy.conf hid the header from upstream responses but did not overwrite the incoming request value in this configuration. An unauthenticated remote attacker could therefore spoof the trusted proxy identity and bypass authentication. This issue is fixed in Mailu 2024.06.55 and Mailu helm-charts 2.7.3.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-290CWE-807

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-09-22: 209-22
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Rıdvan Yağlı@ridvanyagli

    Mailu'da CVE-2026-85751 | CVSS 9.8 Kritik Güvenlik Açığı! Mailu 2.0.0–2024.06.54 sürümlerinde, PROXY_AUTH_WHITELIST yapılandırılmış ancak REAL_IP_HEADER tanımlanmamışsa istemci tarafından spoof edilebilen X-Forwarded-By header'ı üzerinden kimlik doğrulama atlatılabiliyor. 🔴 Uzaktan, kimlik doğrulama gerektirmiyor. ✅ Bu açık, Mailu 2024.06.55 / Helm Charts 2.7.3 ile yamalandı.

    00010333
    2.3K followersView on X
  • Cybersecurity News DE@cybsecuritynews

    #schwachstellen Mailu-Lücke CVE-2026-85751 erlaubt Authentifizierungs-Bypass in Docker-Mailservern #cve202685751 #docker #helm #mailu #nginx https://cybersecurity-news.de/mailu-cve-2026-85751-authentifizierungs-bypass

    000006
    12 followersView on X

Explore more