
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-66141 is a local privilege escalation vulnerability in Exim mail transfer agent affecting versions 4.82 through 4.99.4. The flaw arises from improper handling of the force_command option in pipe transports when processing user .forward files, allowing a local user without special privileges to execute arbitrary commands with elevated rights. It was reported on 2026-06-22, fixed in Exim 4.99.5, and publicly disclosed on 2026-07-22. It carries a CVSS v3.1 base score of 7.4 (High) (Github Advisory, oss-security).
The vulnerability is classified as CWE-829 (Inclusion of Functionality from Untrusted Control Sphere). When Exim is configured with a redirect router that implements .forward file facilities for local users, a pipe transport accessible by that router, and the force_command option set on that pipe transport to run as a privileged user, a local attacker can craft a malicious .forward file using string expansion to influence the command executed by the privileged pipe transport. The specific preconditions required are: a redirect router with .forward support, a pipe transport accessible by that router, force_command set on the pipe transport, and the transport configured to run as a privileged user (oss-security, Github Advisory).
Successful exploitation allows a local user with no special privileges to execute arbitrary commands with elevated (potentially root-level) privileges on the affected mail server. This results in high confidentiality, integrity, and availability impact — an attacker could read sensitive mail data, modify system files, install backdoors, or disrupt mail services. The attack is local in scope but could serve as a stepping stone for broader system compromise or lateral movement within a network (Github Advisory, oss-security).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Github Advisory). The EPSS score is approximately 0.102%, placing it in the 1st percentile for exploitation likelihood within 30 days. The NVD SSVC assessment also indicates no known exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires local access and a specific Exim configuration, which limits the attack surface (Github Advisory).
.forward file support, a pipe transport with force_command set, and that transport configured to run as a privileged user (e.g., root)..forward file: As a local user, create or modify the .forward file in the home directory. Insert a string-expansion expression that, when evaluated by Exim's redirect router, manipulates the command passed to the pipe transport's force_command handler..forward file during delivery, evaluating the string expansion and passing the manipulated command to the privileged pipe transport..forward files in local user home directories containing pipe (|) directives or unusual string-expansion syntax; new files created in privileged directories (e.g., /etc/, /root/) by the Exim process./var/log/exim4/mainlog) showing pipe transport invocations for local users with unusual or unexpected commands; entries referencing force_command execution with unexpected arguments.curl, wget, nc) running as root or another privileged user; unexpected cron jobs or scheduled tasks created by the Exim service account.Upgrade Exim to version 4.99.5 or later, which contains the official fix (oss-security). As an immediate workaround, remove the force_command option from all pipe transports in the Exim configuration, or disable pipe transports entirely if not operationally required. Additionally, review and restrict permissions on .forward files and audit Exim configurations to ensure pipe transports are not configured to run as privileged users unnecessarily (Github Advisory).
The vulnerability was disclosed by Jeremy Harris on behalf of the Exim maintainers via the oss-security mailing list on 2026-07-22, with a coordinated advance notice sent to the distros list on 2026-07-13 (oss-security). Security aggregators including Tenable (Nessus plugins 329376 and 329671), AUSCERT (ESB-2026.8506), INCIBE-CERT, and OSV/Debian have tracked and published advisories for the vulnerability. Community discussion has been limited, consistent with the low EPSS score and absence of public exploit code.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."