CVE-2019-12926: High severity tenable.io vulnerability
MailEnable Enterprise Premium 10.23 did not use appropriate access control checks in a number of areas. As a result, it was possible to perform a number of actions, when logged in as a user, that that user should not have had permission to perform. It was also possible to gain access to areas within the application for which the accounts used were supposed to have insufficient access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-12926?
CVE-2019-12926 has a medium severity level due to improper access control that could lead to unauthorized actions.
How do I fix CVE-2019-12926?
To fix CVE-2019-12926, you should update to the latest version of MailEnable that addresses the access control vulnerabilities.
What versions of MailEnable are affected by CVE-2019-12926?
CVE-2019-12926 affects MailEnable versions from 10.0 to 10.23 and earlier versions in specified ranges.
What are the potential impacts of CVE-2019-12926?
The potential impacts of CVE-2019-12926 include unauthorized access to restricted areas and actions by logged-in users.
Is there a workaround for CVE-2019-12926?
Currently, the best mitigation for CVE-2019-12926 is to apply the available security patch or update to a non-vulnerable version.