Junglewise Threat Intelligence

CVE-2026-41113: Sagredo qmail OS command injection in qmail-remote

CVE-2026-41113 · Severity: high · CVSS 8.1 · Published 2026-04-16

Technologies: Sagredo-Dev Qmail.

Executive brief

Sagredo qmail is a modern distribution of the qmail mail server. A vulnerability in its TLS error handling allows an attacker to execute malicious commands on the mail server by sending an email from a specially configured domain. This could lead to a full system compromise or unauthorized access to email data.

Technical details

A command injection vulnerability exists in qmail-remote.c within the tls_quit() function. When the 'notlshosts_auto' feature is enabled, qmail-remote attempts to record hosts with failed TLS handshakes by executing a shell command via popen(). The command is constructed using sprintf() with the remote hostname (partner_fqdn) wrapped in single quotes. However, an attacker can bypass this by including single quotes and shell metacharacters (like backticks) in a DNS MX record. Because glibc's dn_expand() does not escape these characters, they are passed directly to the shell. An attacker who controls the DNS for a domain can achieve remote code execution as the qmailr user when the victim server attempts to deliver mail to that domain. This issue is fixed in version 2026.04.07.

Affected products

  • sagredo-dev qmail v2024.10.26 through v2026.04.02

Timeline

  • 2026-04-07: patched: Fixed in version v2026.04.07 via commit 749f607
  • 2026-04-16: disclosed: Public disclosure and CVE assignment
  • 2026-04-16: advisory

References