CVE-2026-49217: Mailu missing authentication on PATCH /api/v1/token/<id>, which allows unauthenticated removal of IP restrictions

Published Aug 20, 2026
·
Updated

Mailu is a mail server as a set of Docker images. Prior to version 2024.06.52, a missing authorization check in the Mailu admin REST API allows any unauthenticated attacker to remove any potential IP restriction or update the comment field from any existing user token provided the REST API is enabled. Upgrade to Mailu 2024.06.52 to receive a patch or, as a workaround, turn the REST API off.

Affected Software

1 affected component
Mailu<2024.06.52

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Mailu to a version that resolves this vulnerability.

    Fixed in 2024.06.52
  2. Configuration

    Turn the REST API off as a workaround (prior to version 2024.06.52) to prevent unauthenticated removal of IP restrictions or updating the comment field via PATCH /api/v1/token/<id>.

    Mailu admin REST API REST API enabled = false

Event History

Aug 20, 2026
CVE Published
via MITRE·10:01 PM
Data Sourced
via MITRE·10:01 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Mailu deployments running versions before 2024.06.52 are exposed if the admin REST API is enabled. An attacker can act remotely without authentication, but must target an existing user token.

2

What can an attacker change through the vulnerable endpoint?

An unauthenticated attacker can remove IP restrictions from an existing user token or modify that token's comment field. The issue affects PATCH requests to /api/v1/token/<id>.

3

What should be done if upgrading is not immediately possible?

Turn off the Mailu REST API as a workaround. Upgrading to Mailu 2024.06.52 provides the patch.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203