PatchSiren

Mailu CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Mailu CVE published 2026-08-20

CVE-2026-49217

Mailu is a mail server provided as a set of Docker images. A missing authorization check in the Mailu admin REST API allows unauthenticated attackers to remove IP restrictions or update comments for existing user tokens if the REST API is enabled. This issue was addressed in Mailu version 2024.06.52. Users can upgrade to receive a patch or turn off the REST API as a workaround.