Input validation error in Exim - CVE-2026-94057

 

Input validation error in Exim - CVE-2026-94057

Published: September 29, 2026


Vulnerability identifier: #VU152758
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-94057
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to submit a message different from the one sent and logged by the sending system.

The vulnerability exists due to improper message termination handling in SMTP reception when processing message data after a data-phase rejection. A remote attacker can send a message with crafted data following the rejection point to submit a message different from the one sent and logged by the sending system.

Normal configured processing for received messages is applied to the smuggled message.


Affected software

Exim
Debian Linux
exim4 (Debian package)

How to mitigate CVE-2026-94057

Install security update from vendor's website.

Exim - update to 4.100.1
exim4 (Debian package) - update to 4.98.2-1+deb13u5

External References

Related Security Bulletins