Junglewise Threat Intelligence

CVE-2026-50590: Mimecast Incydr arbitrary file access due to incorrect permissions

CVE-2026-50590 · Severity: medium · CVSS 4.5 · Published 2026-06-05

Executive brief

Mimecast Incydr is a security tool used to monitor and protect corporate data from insider threats. A vulnerability in versions prior to 2.6.0 could allow an unauthorized user on a local system to access sensitive files they should not be able to see. This could lead to the exposure of internal company information or configuration data.

Technical details

A vulnerability exists in Mimecast Incydr (formerly Code42) before version 2.6.0 due to incorrect permission assignment for critical resources (CWE-732). An attacker with local access to the system could exploit this flaw to gain unauthorized access to arbitrary files. The attack complexity is considered high, likely requiring specific timing or environmental conditions to successfully bypass intended access controls. The issue is resolved in version 2.6.0 and later.

Affected products

  • Mimecast Incydr Agent before 2.6.0

Timeline

  • 2026-06-05: disclosed
  • 2026-06-05: advisory

References