PatchSiren cyber security CVE debrief
CVE-2026-67448 axllent CVE debrief
Mailpit, an email testing tool and API for developers, had a vulnerability from version 1.29.0 until 1.30.6. A malicious website could request /%61pi/events, bypassing CORS origin access control, and reach the /api/events WebSocket handler in an unauthenticated default Mailpit instance. This allowed the site to receive live message IDs, Message-Id values, sender and recipient fields, subjects, tags, and body snippets after a user visited the site. This issue is a regression of earlier WebSocket origin protection and does not affect deployments protected by --ui-auth-file. The vulnerability is fixed in version 1.30.6.
- Vendor
- axllent
- Product
- mailpit
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-20
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-08-20
- Advisory updated
- 2026-09-18
Who should care
Defenders of Mailpit instances, especially those not protected by --ui-auth-file, should assess exposure and prioritize upgrading to version 1.30.6. This includes Mailpit administrators, security teams, and operators who manage Mailpit instances. They should verify instance configurations, monitor for unauthorized access, and ensure that compensating controls are in place for exposed systems.
Why it matters
Defenders should care about CVE-2026-67448 because it allows unauthorized access to sensitive email data in Mailpit instances not protected by --ui-auth-file. The vulnerability enables a malicious website to bypass CORS origin access control and receive live message data. Defenders of Mailpit instances should assess exposure, prioritize upgrading to version 1.30.6, and monitor for unauthorized access.
- Potential unauthorized access to sensitive email data.
- Possible information disclosure through live message IDs and content.
- Bypassing of CORS origin access control.
- Verification of Mailpit instance security configurations.
Technical summary
The vulnerability in Mailpit from version 1.29.0 until 1.30.6 allows a malicious website to bypass CORS origin access control and receive live message data from an unauthenticated default Mailpit instance via WebSocket. This issue is a regression of earlier WebSocket origin protection and does not affect deployments protected by --ui-auth-file. The vulnerability is fixed in version 1.30.6. Defenders should prioritize verifying exposure of Mailpit instances, especially those not protected by --ui-auth-file, and upgrade to version 1.30.6 if vulnerable.
Defensive priority
Defenders should prioritize verifying exposure of Mailpit instances, especially those not protected by --ui-auth-file, and upgrade to version 1.30.6 if vulnerable.
Recommended defensive actions
- Verify Mailpit instance exposure, especially those not protected by --ui-auth-file.
- Upgrade vulnerable instances to version 1.30.6.
- Monitor for unauthorized access to Mailpit instances.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record and NVD detail page provide information on the vulnerability, its impact, and the fix. References include commits, release notes, and security advisories. Defenders should verify Mailpit instance configurations, especially those not protected by --ui-auth-file, and assess exposure to this vulnerability. The vulnerability allows a malicious website to bypass CORS origin access control and receive live message data from an unauthenticated default Mailpit instance via WebSocket.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-67448 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-67448
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-67448 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-67448
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/axllent/mailpit/commit/fbe5e006c3f1682b819df58b4a932d7a84920be9
-
Source reference
Unverified legacy reference
URL: https://github.com/axllent/mailpit/releases/tag/v1.30.6
-
Source reference
Unverified legacy reference
URL: https://github.com/axllent/mailpit/security/advisories/GHSA-8r62-w5wh-fc5m
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.