CVE-2026-66141
Exim vulnerability analysis and mitigation

Overview

CVE-2026-66141 is a local privilege escalation vulnerability in Exim mail transfer agent affecting versions 4.82 through 4.99.4. The flaw arises from improper handling of the force_command option in pipe transports when processing user .forward files, allowing a local user without special privileges to execute arbitrary commands with elevated rights. It was reported on 2026-06-22, fixed in Exim 4.99.5, and publicly disclosed on 2026-07-22. It carries a CVSS v3.1 base score of 7.4 (High) (Github Advisory, oss-security).

Technical details

The vulnerability is classified as CWE-829 (Inclusion of Functionality from Untrusted Control Sphere). When Exim is configured with a redirect router that implements .forward file facilities for local users, a pipe transport accessible by that router, and the force_command option set on that pipe transport to run as a privileged user, a local attacker can craft a malicious .forward file using string expansion to influence the command executed by the privileged pipe transport. The specific preconditions required are: a redirect router with .forward support, a pipe transport accessible by that router, force_command set on the pipe transport, and the transport configured to run as a privileged user (oss-security, Github Advisory).

Impact

Successful exploitation allows a local user with no special privileges to execute arbitrary commands with elevated (potentially root-level) privileges on the affected mail server. This results in high confidentiality, integrity, and availability impact — an attacker could read sensitive mail data, modify system files, install backdoors, or disrupt mail services. The attack is local in scope but could serve as a stepping stone for broader system compromise or lateral movement within a network (Github Advisory, oss-security).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Github Advisory). The EPSS score is approximately 0.102%, placing it in the 1st percentile for exploitation likelihood within 30 days. The NVD SSVC assessment also indicates no known exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires local access and a specific Exim configuration, which limits the attack surface (Github Advisory).

Exploitation steps

  1. Reconnaissance: Identify a target system running Exim versions 4.82–4.99.4 with local user access. Confirm the Exim configuration includes a redirect router with .forward file support, a pipe transport with force_command set, and that transport configured to run as a privileged user (e.g., root).
  2. Craft malicious .forward file: As a local user, create or modify the .forward file in the home directory. Insert a string-expansion expression that, when evaluated by Exim's redirect router, manipulates the command passed to the pipe transport's force_command handler.
  3. Trigger mail delivery: Send an email to the local user account. Exim processes the .forward file during delivery, evaluating the string expansion and passing the manipulated command to the privileged pipe transport.
  4. Achieve privilege escalation: The pipe transport executes the attacker-controlled command with the elevated privileges configured for that transport, resulting in arbitrary command execution as a privileged user (oss-security).

Indicators of compromise

  • File System: Unexpected or recently modified .forward files in local user home directories containing pipe (|) directives or unusual string-expansion syntax; new files created in privileged directories (e.g., /etc/, /root/) by the Exim process.
  • Logs: Exim mail logs (/var/log/exim4/mainlog) showing pipe transport invocations for local users with unusual or unexpected commands; entries referencing force_command execution with unexpected arguments.
  • Process: Unusual child processes spawned by the Exim daemon (e.g., shells, network tools like curl, wget, nc) running as root or another privileged user; unexpected cron jobs or scheduled tasks created by the Exim service account.
  • Network: Outbound connections from the mail server to unknown external IPs initiated by processes spawned from Exim, potentially indicating reverse shell activity.

Mitigation and workarounds

Upgrade Exim to version 4.99.5 or later, which contains the official fix (oss-security). As an immediate workaround, remove the force_command option from all pipe transports in the Exim configuration, or disable pipe transports entirely if not operationally required. Additionally, review and restrict permissions on .forward files and audit Exim configurations to ensure pipe transports are not configured to run as privileged users unnecessarily (Github Advisory).

Community reactions

The vulnerability was disclosed by Jeremy Harris on behalf of the Exim maintainers via the oss-security mailing list on 2026-07-22, with a coordinated advance notice sent to the distros list on 2026-07-13 (oss-security). Security aggregators including Tenable (Nessus plugins 329376 and 329671), AUSCERT (ESB-2026.8506), INCIBE-CERT, and OSV/Debian have tracked and published advisories for the vulnerability. Community discussion has been limited, consistent with the low EPSS score and absence of public exploit code.

Additional resources


SourceThis report was generated using AI

Related Exim vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45185CRITICAL9.8
  • Exim logoExim
  • exim-mon
NoYesMay 12, 2026
CVE-2026-40687CRITICAL9.1
  • Exim logoExim
  • exim-mysql
NoYesApr 30, 2026
CVE-2026-66140HIGH8.4
  • Exim logoExim
  • cpe:2.3:a:exim:exim
NoYesJul 24, 2026
CVE-2026-66141HIGH7.4
  • Exim logoExim
  • exim
NoYesJul 24, 2026
CVE-2026-48840MEDIUM5.3
  • Exim logoExim
  • exim
NoYesMay 30, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management