CVE-2026-85751

9.8

Mailu · Mailu

Mailu deployments with specific proxy configurations allow unauthenticated remote attackers to spoof trusted proxy identities and bypass authentication via the X-Forwarded-By header.

Executive summary

A critical authentication bypass vulnerability in Mailu allows unauthenticated remote attackers to gain full access by spoofing trusted proxy headers.

Vulnerability

This vulnerability involves an authentication bypass due to the improper handling of the X-Forwarded-By header in specific proxy configurations. An unauthenticated remote attacker can exploit this flaw to spoof trusted proxy identities, effectively bypassing security controls.

Business impact

This vulnerability carries a CVSS score of 9.8, indicating a critical risk to organizational security. Successful exploitation grants an attacker full, unauthorized access to the mail server, which could lead to the total compromise of sensitive communications, unauthorized data exfiltration, and complete system takeover.

Remediation

Immediate Action: Upgrade Mailu to version 2024.06.55 or higher, and update Mailu helm-charts to version 2.7.3 or higher.

Proactive Monitoring: Review web server access logs for anomalous requests containing modified X-Forwarded-By headers or unexpected source IP addresses.

Compensating Controls: If immediate patching is not feasible, ensure that the REAL_IP_HEADER directive is correctly configured to validate incoming traffic and restrict access to the affected management interfaces at the network perimeter.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical nature of this authentication bypass and its potential for full system compromise, immediate remediation is mandatory. IT administrators should prioritize applying the provided updates to all Mailu instances, as no other mitigation offers equivalent protection against this high-severity threat.

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources