CVE-2026-6351
7.5Openfind · MailGates and MailAudit
Openfind MailGates and MailAudit are affected by a CRLF injection vulnerability, enabling unauthenticated remote attackers to read sensitive system files.
Executive summary
A critical CRLF injection vulnerability in Openfind MailGates and MailAudit allows unauthenticated remote attackers to gain unauthorized access to system files.
Vulnerability
The software fails to properly neutralize CRLF sequences, which allows an unauthenticated remote attacker to manipulate HTTP headers or responses to facilitate unauthorized file access.
Business impact
The ability for an unauthenticated attacker to read system files poses a severe risk to confidentiality and system integrity. Given the CVSS score of 7.5, this high severity vulnerability could lead to the exposure of configuration files, credentials, or other sensitive data, resulting in a significant compromise of the organizational mail infrastructure.
Remediation
Immediate Action: Update Openfind MailGates and MailAudit to version 6.1.10.054 or 5.2.10.099 as appropriate for your current release branch.
Proactive Monitoring: Review web application access logs for unusual patterns or characters, specifically searching for CRLF sequences or unexpected file path requests.
Compensating Controls: Deploy a Web Application Firewall (WAF) configured to inspect and block requests containing CRLF sequences to mitigate the risk until patches are applied.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability represents a significant security risk due to the potential for unauthorized file access without the need for authentication. Administrators should prioritize the deployment of the provided vendor patches immediately to eliminate this vector. Failure to update leaves the mail gateway susceptible to information disclosure that could facilitate further network compromise.