PT-2026-96145 · Mailu+1 · Mailu+1

CVE-2026-85751

·

Published

2026-09-21

·

Updated

2026-09-23

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mailu versions 2.0 through 2024.06.54 Mailu helm-charts versions prior to 2.7.3
Description Deployments configured with PROXY AUTH WHITELIST but without REAL IP HEADER set trust a client-controlled X-Forwarded-By header for proxy authentication. The proxy hide header directive in the nginx template at core/nginx/conf/proxy.conf hides the header from upstream responses but fails to overwrite the incoming request value. This allows an unauthenticated remote attacker to spoof the trusted proxy identity and bypass authentication.
Recommendations Update Mailu to version 2024.06.55. Update Mailu helm-charts to version 2.7.3.

Exploit

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85751
GHSA-RFHJ-4WCQ-74XG

Affected Products

Mailu
Mailu Helm-Charts