CVE-2026-70408: High severity acmailer vulnerability
Published Aug 19, 2026
·Updated
An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has administrative privileges.
Affected Software
1 affected component
acmailer
Event History
Aug 19, 2026
CVE Published
via MITRE·04:54 AM
Data Sourced
via MITRE·04:54 AM
DescriptionSeverity
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability requires low privileges. A user who can access the relevant account-creation functionality may be able to create a sub-account with administrative privileges.
2
What is the potential impact if exploitation succeeds?
Successful exploitation can result in a sub-account receiving administrative privileges. The reported CVSS vector indicates high impact to confidentiality, integrity, and availability.