CVE-2025-26794: high-severity vulnerability in Exim
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Exim 4.98 before 4.98.1 allows an attacker to inject malicious SQL commands through the email server when specific features (SQLite hints and ETRN serialization) are enabled. This could let someone access or modify the server's database without proper authorization.
SQL injection vulnerability in Exim 4.98 prior to 4.98.1 when SQLite hints and ETRN serialization are configured. Attack vector requires remote network access to the mail server with these non-default features enabled; successful exploitation permits unauthorized database query execution and potential data exfiltration or manipulation.
In the same product, most dangerous first.