PT-2026-96145 · Mailu+1 · Mailu+1
CVE-2026-85751
·
Published
2026-09-21
·
Updated
2026-09-23
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Mailu versions 2.0 through 2024.06.54
Mailu helm-charts versions prior to 2.7.3
Description
Deployments configured with
PROXY AUTH WHITELIST but without REAL IP HEADER set trust a client-controlled X-Forwarded-By header for proxy authentication. The proxy hide header directive in the nginx template at core/nginx/conf/proxy.conf hides the header from upstream responses but fails to overwrite the incoming request value. This allows an unauthenticated remote attacker to spoof the trusted proxy identity and bypass authentication.Recommendations
Update Mailu to version 2024.06.55.
Update Mailu helm-charts to version 2.7.3.
Exploit
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mailu
Mailu Helm-Charts