Junglewise Threat Intelligence

CVE-2026-6351: Openfind MailGates/MailAudit CRLF injection file disclosure

CVE-2026-6351 · Severity: high · CVSS 7.5 · Published 2026-04-16

Executive brief

Openfind MailGates and MailAudit, which are email security and auditing solutions, contain a vulnerability that allows unauthorized individuals to access internal system files. An attacker could exploit this to view sensitive configuration data or system information without needing a username or password. This could lead to further compromise of the email infrastructure or the exposure of confidential operational data.

Technical details

A CRLF (Carriage Return Line Feed) injection vulnerability exists in Openfind MailGates and MailAudit versions 5.0 (prior to 5.2.10.099) and 6.0 (prior to 6.1.10.054). The flaw stems from improper neutralization of CRLF sequences (CWE-93), which can be manipulated by an unauthenticated remote attacker via network requests. Successful exploitation allows the attacker to bypass intended access controls to read arbitrary system files on the underlying host. Users are advised to update to versions 5.2.10.099 or 6.1.10.054 respectively to mitigate this risk.

Affected products

  • Openfind MailGates/MailAudit 5.0 Before version 5.2.10.099
  • Openfind MailGates/MailAudit 6.0 Before version 6.1.10.054

Timeline

  • 2026-04-16: disclosed
  • 2026-04-16: advisory
  • 2026-04-16: patched

References

Related threats