
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-66140 is a directory traversal vulnerability in Exim mail transfer agent that allows local attackers to access files outside the spool area and consequently escalate privileges. It affects Exim versions 4.88 through 4.99.4 (released 2017 onward), and was corrected in Exim 4.99.5. The vulnerability was publicly disclosed on July 22, 2026, via the oss-security mailing list, with NVD publication on July 24, 2026. It carries a CVSS v3.1 base score of 8.4 (High) (GitHub Advisory, oss-security).
The root cause is improper handling of queue-name arguments passed through the Exim execution chain (CWE-24: Path Traversal ../filedir). When command-line arguments intended for transferring queue-name between Exim processes are processed, insufficient sanitization of ../ sequences allows an attacker with command-line access to traverse outside the designated spool directory and read or manipulate arbitrary files. The vulnerability is tracked under Exim's internal identifier EXIM-Security-2026-06-22.1 and requires only local command-line access with no privileges, no user interaction, and low attack complexity (oss-security, GitHub Advisory).
Successful exploitation allows a local unauthenticated attacker to access files outside the Exim spool area, enabling privilege escalation on the affected system. The CVSS scoring reflects high impacts to confidentiality, integrity, and availability, meaning an attacker could read sensitive mail data or system files, modify files to gain elevated privileges, and potentially disrupt mail service operations. All Exim installations running versions 4.88 through 4.99.4 where an attacker has command-line access are affected (oss-security, GitHub Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation, per NVD SSVC assessment (exploitation: none) (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.272% (19th percentile), indicating a relatively low near-term exploitation probability. Exploitation requires local command-line access, which limits the attack surface compared to remotely exploitable vulnerabilities (GitHub Advisory).
/var/spool/exim4/) using exim --version or by inspecting configuration files.../../etc/shadow or similar) to reference files outside the spool area./var/log/exim4/mainlog) showing unusual queue-name values containing ../ sequences or references to paths outside /var/spool/exim4/; system audit logs (auditd) recording Exim process access to unexpected file paths./etc/shadow, /etc/passwd) coinciding with Exim process activity; new or modified files in privileged directories created by the Exim service account.The only resolution is to upgrade Exim to version 4.99.5 or later, available from the official Exim FTP server and code repository. No configuration-based workaround exists for this specific vulnerability — the oss-security advisory explicitly states "Mitigations: None." As a defense-in-depth measure, administrators should restrict local command-line access to Exim binaries and enforce filesystem permissions on the spool directory to limit exposure (oss-security, GitHub Advisory).
The vulnerability was disclosed by Jeremy Harris on behalf of the Exim maintainers via the oss-security mailing list on July 22, 2026, following a coordinated disclosure process that included advance notice to the distros mailing list on July 13, 2026. Debian issued an update for the exim4 package, and the vulnerability was picked up by security aggregators including Tenable (Nessus plugins 329376 and 329601), AUSCERT (ESB-2026.8506), and INCIBE-CERT. Community discussion on Mastodon noted the release, though overall social media reaction has been limited given the local-only attack vector (oss-security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."