PatchSiren cyber security CVE debrief
CVE-2026-41113 sagredo CVE debrief
A command injection vulnerability exists in sagredo qmail before version 2026.04.07. The flaw resides in the `notlshosts_auto` function within `qmail-remote.c`, which uses `popen()` to execute a command constructed with attacker-influenced input from the `tls_quit` mechanism. This allows remote unauthenticated attackers to achieve code execution on affected mail servers. The vulnerability was disclosed in April 2026 and subsequently patched. The CVSS 3.1 score of 8.1 reflects high impact despite requiring high attack complexity.
- Vendor
- sagredo
- Product
- qmail
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-16
- Original CVE updated
- 2026-05-19
- Advisory published
- 2026-04-16
- Advisory updated
- 2026-05-19
Who should care
Organizations operating sagredo qmail installations as mail transfer agents, particularly those exposed to untrusted networks. Security teams responsible for mail infrastructure and vulnerability management programs should prioritize patching given the HIGH severity rating and potential for unauthenticated remote compromise.
Technical summary
The vulnerability stems from unsafe use of `popen()` in `qmail-remote.c`'s `notlshosts_auto` function. The `tls_quit` parameter, which can be influenced by remote TLS handshake behavior, is incorporated into a shell command without adequate sanitization. This classic command injection pattern enables arbitrary code execution with the privileges of the qmail-remote process. The attack requires network access to the mail server and successful TLS negotiation, contributing to the high attack complexity rating. The fix eliminates the unsafe `popen()` usage in favor of safer alternatives.
Defensive priority
HIGH
Recommended defensive actions
- Upgrade sagredo qmail to version 2026.04.07 or later to remediate this vulnerability.
- Review mail server configurations to confirm deployment of patched versions.
- Monitor for anomalous process execution or network connections originating from qmail-remote processes.
- Consider network segmentation for mail transfer agents to limit exposure of this attack surface.
Evidence notes
The vulnerability was identified through security research involving automated auditing. The fix was committed to the sagredo-dev/qmail repository and released as version 2026.04.07. The NVD record shows deferred status as of the last modification date.
Official resources
-
CVE-2026-41113 CVE record
CVE.org
-
CVE-2026-41113 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
- Source reference
- Source reference
- Source reference
- Source reference
-
Source reference
af854a3a-2127-422b-91ae-364da2661108
2026-04-16