216.73.216.6

CVE-2026-7460

· Published 20/05/2026 04:16 · Modified 20/05/2026 14:23

Labels: CVE-2026-7460 2026-05-20CVE-2026-7460CWE-79[email protected]

Essential information

Published
20/05/2026 04:16
Modified
20/05/2026 14:23
Author
Creator
CVSS
7.4 HIGH (v3) 7.4 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

mailcow-dockerized contains a stored cross-site scripting vulnerability in the administrator Queue Manager. The Queue Manager fetches mail queue entries from /api/v1/get/mailq/all, copies server-controlled Postfix queue fields into DataTables rows, and renders several of those fields as HTML without adequate output encoding. This issue affects mailcow-dockerized: 2026-03b.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
mailcow / mailcow-dockerized cpe:2.3:a:mailcow:mailcow-dockerized:2026-03b:*:*:*:*:*:*:*

References