PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-67448 axllent CVE debrief

Mailpit, an email testing tool and API for developers, had a vulnerability from version 1.29.0 until 1.30.6. A malicious website could request /%61pi/events, bypassing CORS origin access control, and reach the /api/events WebSocket handler in an unauthenticated default Mailpit instance. This allowed the site to receive live message IDs, Message-Id values, sender and recipient fields, subjects, tags, and body snippets after a user visited the site. This issue is a regression of earlier WebSocket origin protection and does not affect deployments protected by --ui-auth-file. The vulnerability is fixed in version 1.30.6.

Vendor
axllent
Product
mailpit
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-20
Original CVE updated
2026-09-18
Advisory published
2026-08-20
Advisory updated
2026-09-18

Who should care

Defenders of Mailpit instances, especially those not protected by --ui-auth-file, should assess exposure and prioritize upgrading to version 1.30.6. This includes Mailpit administrators, security teams, and operators who manage Mailpit instances. They should verify instance configurations, monitor for unauthorized access, and ensure that compensating controls are in place for exposed systems.

Why it matters

Defenders should care about CVE-2026-67448 because it allows unauthorized access to sensitive email data in Mailpit instances not protected by --ui-auth-file. The vulnerability enables a malicious website to bypass CORS origin access control and receive live message data. Defenders of Mailpit instances should assess exposure, prioritize upgrading to version 1.30.6, and monitor for unauthorized access.

  • Potential unauthorized access to sensitive email data.
  • Possible information disclosure through live message IDs and content.
  • Bypassing of CORS origin access control.
  • Verification of Mailpit instance security configurations.

Technical summary

The vulnerability in Mailpit from version 1.29.0 until 1.30.6 allows a malicious website to bypass CORS origin access control and receive live message data from an unauthenticated default Mailpit instance via WebSocket. This issue is a regression of earlier WebSocket origin protection and does not affect deployments protected by --ui-auth-file. The vulnerability is fixed in version 1.30.6. Defenders should prioritize verifying exposure of Mailpit instances, especially those not protected by --ui-auth-file, and upgrade to version 1.30.6 if vulnerable.

Defensive priority

Defenders should prioritize verifying exposure of Mailpit instances, especially those not protected by --ui-auth-file, and upgrade to version 1.30.6 if vulnerable.

Recommended defensive actions

  • Verify Mailpit instance exposure, especially those not protected by --ui-auth-file.
  • Upgrade vulnerable instances to version 1.30.6.
  • Monitor for unauthorized access to Mailpit instances.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and NVD detail page provide information on the vulnerability, its impact, and the fix. References include commits, release notes, and security advisories. Defenders should verify Mailpit instance configurations, especially those not protected by --ui-auth-file, and assess exposure to this vulnerability. The vulnerability allows a malicious website to bypass CORS origin access control and receive live message data from an unauthenticated default Mailpit instance via WebSocket.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-67448 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-67448

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-67448 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-67448

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.