CVE-2026-66140
Exim vulnerability analysis and mitigation

Overview

CVE-2026-66140 is a directory traversal vulnerability in Exim mail transfer agent that allows local attackers to access files outside the spool area and consequently escalate privileges. It affects Exim versions 4.88 through 4.99.4 (released 2017 onward), and was corrected in Exim 4.99.5. The vulnerability was publicly disclosed on July 22, 2026, via the oss-security mailing list, with NVD publication on July 24, 2026. It carries a CVSS v3.1 base score of 8.4 (High) (GitHub Advisory, oss-security).

Technical details

The root cause is improper handling of queue-name arguments passed through the Exim execution chain (CWE-24: Path Traversal ../filedir). When command-line arguments intended for transferring queue-name between Exim processes are processed, insufficient sanitization of ../ sequences allows an attacker with command-line access to traverse outside the designated spool directory and read or manipulate arbitrary files. The vulnerability is tracked under Exim's internal identifier EXIM-Security-2026-06-22.1 and requires only local command-line access with no privileges, no user interaction, and low attack complexity (oss-security, GitHub Advisory).

Impact

Successful exploitation allows a local unauthenticated attacker to access files outside the Exim spool area, enabling privilege escalation on the affected system. The CVSS scoring reflects high impacts to confidentiality, integrity, and availability, meaning an attacker could read sensitive mail data or system files, modify files to gain elevated privileges, and potentially disrupt mail service operations. All Exim installations running versions 4.88 through 4.99.4 where an attacker has command-line access are affected (oss-security, GitHub Advisory).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation, per NVD SSVC assessment (exploitation: none) (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.272% (19th percentile), indicating a relatively low near-term exploitation probability. Exploitation requires local command-line access, which limits the attack surface compared to remotely exploitable vulnerabilities (GitHub Advisory).

Exploitation steps

  1. Gain local access: Obtain command-line access to a system running Exim 4.88–4.99.4 (e.g., via a low-privileged shell account or another vulnerability).
  2. Identify Exim installation: Confirm the Exim version and spool directory location (typically /var/spool/exim4/) using exim --version or by inspecting configuration files.
  3. Craft malicious queue-name argument: Construct a command-line invocation of Exim that passes a queue-name argument containing path traversal sequences (e.g., ../../etc/shadow or similar) to reference files outside the spool area.
  4. Trigger directory traversal: Execute Exim with the crafted queue-name argument, causing Exim to process or expose the targeted file outside the spool directory boundary.
  5. Leverage file access for privilege escalation: Use the unauthorized file access to read sensitive credentials, modify configuration files, or plant payloads that result in elevated privilege execution (oss-security).

Indicators of compromise

  • Logs: Exim log entries (/var/log/exim4/mainlog) showing unusual queue-name values containing ../ sequences or references to paths outside /var/spool/exim4/; system audit logs (auditd) recording Exim process access to unexpected file paths.
  • Process: Exim processes spawned with anomalous command-line arguments referencing paths outside the spool directory; unexpected child processes or privilege changes associated with the Exim daemon.
  • File System: Unexpected access timestamps on sensitive files (e.g., /etc/shadow, /etc/passwd) coinciding with Exim process activity; new or modified files in privileged directories created by the Exim service account.

Mitigation and workarounds

The only resolution is to upgrade Exim to version 4.99.5 or later, available from the official Exim FTP server and code repository. No configuration-based workaround exists for this specific vulnerability — the oss-security advisory explicitly states "Mitigations: None." As a defense-in-depth measure, administrators should restrict local command-line access to Exim binaries and enforce filesystem permissions on the spool directory to limit exposure (oss-security, GitHub Advisory).

Community reactions

The vulnerability was disclosed by Jeremy Harris on behalf of the Exim maintainers via the oss-security mailing list on July 22, 2026, following a coordinated disclosure process that included advance notice to the distros mailing list on July 13, 2026. Debian issued an update for the exim4 package, and the vulnerability was picked up by security aggregators including Tenable (Nessus plugins 329376 and 329601), AUSCERT (ESB-2026.8506), and INCIBE-CERT. Community discussion on Mastodon noted the release, though overall social media reaction has been limited given the local-only attack vector (oss-security).

Additional resources


SourceThis report was generated using AI

Related Exim vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45185CRITICAL9.8
  • Exim logoExim
  • exim-mon
NoYesMay 12, 2026
CVE-2026-40687CRITICAL9.1
  • Exim logoExim
  • exim-mysql
NoYesApr 30, 2026
CVE-2026-66140HIGH8.4
  • Exim logoExim
  • cpe:2.3:a:exim:exim
NoYesJul 24, 2026
CVE-2026-66141HIGH7.4
  • Exim logoExim
  • exim
NoYesJul 24, 2026
CVE-2026-48840MEDIUM5.3
  • Exim logoExim
  • exim
NoYesMay 30, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management