Path traversal in Exim - #VU139245
Published: July 23, 2026
Exim
Detailed vulnerability description
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to path traversal in command-line queue-name handling when processing command-line arguments intended for transferring queue-name through an Exim execution chain. A local user can supply crafted command-line arguments to escalate privileges.
To reach the vulnerable code, command-line access on the system is required.