<Vulnerability name="CVE-2026-66140">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-07-24T04:32:08</PublicDate>
    <Bugzilla id="2506674" url="https://bugzilla.redhat.com/show_bug.cgi?id=2506674" xml:lang="en:us">
exim: Exim: Privilege escalation via directory traversal due to mishandled queue-name arguments
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>8.4</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-22</CWE>
    <Details xml:lang="en:us" source="Mitre">
Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Exim. This vulnerability allows an attacker to perform directory traversal by mishandling arguments related to queue-name. This could enable unauthorized access to files outside of the designated spool area, potentially leading to a gain of privileges.
    </Details>
    <Statement xml:lang="en:us">
This Important flaw in Exim allows a local, unprivileged attacker to achieve privilege escalation through directory traversal. By exploiting mishandled queue-name arguments, an attacker can access sensitive files outside the intended spool area, increasing the risk of system compromise.
    </Statement>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
    </Mitigation>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-66140
https://nvd.nist.gov/vuln/detail/CVE-2026-66140
https://openwall.com/lists/oss-security/2026/07/22/9
    </References>
</Vulnerability>