EIP-2026-103098
PRE-CVEDovecot with Exim - 'sender_address' Remote Command Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-103098. PoCs published by RedTeam Pentesting GmbH.
AI-analyzed exploit summary This advisory details a misconfiguration in Exim when using Dovecot as a local delivery agent, where the 'use_shell' option in the pipe transport allows remote command execution via crafted sender addresses. The vulnerability arises from improper handling of shell metacharacters in the $sender_address variable.
Description
Dovecot with Exim - 'sender_address' Remote Command Execution
Exploits (1)
This advisory details a misconfiguration in Exim when using Dovecot as a local delivery agent, where the 'use_shell' option in the pipe transport allows remote command execution via crafted sender addresses. The vulnerability arises from improper handling of shell metacharacters in the $sender_address variable.