What is CVE-2026-66140?
Exim versions before 4.99.5 contain a directory traversal vulnerability due to mishandling of `queue-name` arguments, allowing access to files outside the spool area. This can be exploited to gain elevated privileges, making immediate patching essential.
Azərbaycanca: Exim poçt serverinin 4.99.5-dən əvvəlki versiyalarında `queue-name` arqumentlərinin düzgün yoxlanılmaması səbəbindən directory traversal zəifliyi mövcuddur. Bu, təcavüzkara spool sahəsindən kənar fayllara giriş əldə edərək imtiyazları artırmağa imkan yaradır. Dərhal Exim-i ən son versiyaya yeniləmək lazımdır.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which versions of Exim are affected by CVE-2026-66140?
Exim versions prior to 4.99.5 are affected.
How to protect against CVE-2026-66140?
To prevent an attacker from gaining unauthorized file access and escalating privileges, immediate patching of Exim to the latest version is essential.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.