CVE-2026-6351

7.5

Openfind · MailGates and MailAudit

Openfind MailGates and MailAudit are affected by a CRLF injection vulnerability, enabling unauthenticated remote attackers to read sensitive system files.

Executive summary

A critical CRLF injection vulnerability in Openfind MailGates and MailAudit allows unauthenticated remote attackers to gain unauthorized access to system files.

Vulnerability

The software fails to properly neutralize CRLF sequences, which allows an unauthenticated remote attacker to manipulate HTTP headers or responses to facilitate unauthorized file access.

Business impact

The ability for an unauthenticated attacker to read system files poses a severe risk to confidentiality and system integrity. Given the CVSS score of 7.5, this high severity vulnerability could lead to the exposure of configuration files, credentials, or other sensitive data, resulting in a significant compromise of the organizational mail infrastructure.

Remediation

Immediate Action: Update Openfind MailGates and MailAudit to version 6.1.10.054 or 5.2.10.099 as appropriate for your current release branch.

Proactive Monitoring: Review web application access logs for unusual patterns or characters, specifically searching for CRLF sequences or unexpected file path requests.

Compensating Controls: Deploy a Web Application Firewall (WAF) configured to inspect and block requests containing CRLF sequences to mitigate the risk until patches are applied.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability represents a significant security risk due to the potential for unauthorized file access without the need for authentication. Administrators should prioritize the deployment of the provided vendor patches immediately to eliminate this vector. Failure to update leaves the mail gateway susceptible to information disclosure that could facilitate further network compromise.

Sources