securityonline.info 7/22/2026, 7:08:03 PM · external

Exim flaw lets local users read files, patched in 4.99.5

Exim flaw lets local users read files, patched in 4.99.5
CyberSIXT Evidence Panel
Primary Source exim.org

THE Exim team issued advisory EXIM-Security-2026-06-22.1 describing a critical vulnerability that allows local attackers to read files outside the mail spool, potentially leading to privilege escalation. This issue affects Exim versions 4.88 to 4.99.4, and has been patched in version 4.99.5. The vulnerability arises from improper handling of queue names, which can be exploited via command-line access. There have been no confirmed exploitations in the wild, and the advised solution is to upgrade to the latest patched version.

View Primary Source Via securityonline.info

Article by CyberSIXT