https://seclists.org/oss-sec/2025/q1/154: CVE-2025-26794: Exim: SQL injection
Published Feb 21, 2025
·Updated
Affected Software
1 affected component
Exim Exim
Frequently Asked Questions
1
What is the severity of CVE-2025-26794?
CVE-2025-26794 has been classified with a critical severity rating due to the potential for remote code execution through SQL injection.
2
How do I fix CVE-2025-26794?
To mitigate CVE-2025-26794, update to the latest version of Exim, specifically exim-4.98.1 or later, which contains the security fix.
3
What systems are affected by CVE-2025-26794?
CVE-2025-26794 affects Exim versions prior to 4.98.1, especially those configured to process SQL queries.
4
What type of vulnerability is CVE-2025-26794?
CVE-2025-26794 is categorized as an SQL injection vulnerability that allows attackers to manipulate database queries.
5
When was CVE-2025-26794 disclosed?
CVE-2025-26794 was disclosed on February 21, 2025, coinciding with the release of a security patch for Exim.