CVE-2025-26794highCWE-89

CVE-2025-26794: high-severity vulnerability in Exim

Published · Updated

43Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.5epss 78%
exploitation probability
78%top 1% of all CVEs
observed exploitation
nono source reports it
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Not affected
1 product — because the vulnerable code is not present in the product
red_hat_products
In short

Exim 4.98 before 4.98.1 allows an attacker to inject malicious SQL commands through the email server when specific features (SQLite hints and ETRN serialization) are enabled. This could let someone access or modify the server's database without proper authorization.

Technical detail

SQL injection vulnerability in Exim 4.98 prior to 4.98.1 when SQLite hints and ETRN serialization are configured. Attack vector requires remote network access to the mail server with these non-default features enabled; successful exploitation permits unauthorized database query execution and potential data exfiltration or manipulation.

Summary generated and translated by AI from the official description.
Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection. (Resolving SQL injection requires an update to 4.99.1 in certain non-default rate-limit configurations.)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
Exim · Exim