Junglewise Threat Intelligence

CVE-2026-7460: mailcow mailcow-dockerized stored XSS in Queue Manager

CVE-2026-7460 · Severity: info · CVSS 7.4 · Published 2026-05-20

Executive brief

mailcow-dockerized is an open-source mail server suite. A vulnerability in its administrator Queue Manager allows malicious scripts to be stored and executed when an administrator views the mail queue. This could lead to unauthorized actions being performed in the context of the administrator's session, potentially compromising the mail server's configuration or sensitive data.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the Queue Manager component of mailcow-dockerized version 2026-03b. The vulnerability is located in the way the application handles mail queue data fetched from the `/api/v1/get/mailq/all` endpoint. Specifically, server-controlled Postfix queue fields are copied into DataTables rows and rendered as HTML without sufficient output encoding. An attacker who can influence mail queue metadata (such as sender or recipient fields) can inject malicious JavaScript that executes when an administrator accesses the Queue Manager interface. This requires low privileges to initiate the mail but relies on an administrator viewing the affected page.

Affected products

  • mailcow mailcow-dockerized 2026-03b

Timeline

  • 2026-05-20: advisory: NVD publication date

References