CVE-2026-70408
Deferred Deferred - Pending Action

Incorrect Authorization in acmailer Allows Privilege Escalation

Vulnerability report for CVE-2026-70408, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-28

Assigner: JPCERT/CC

Description

An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has administrative privileges.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-28
Generated
2026-09-08
AI Q&A
2026-08-19
EPSS Evaluated
2026-09-07
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
extra_innovation_inc acmailer to 4.1.2 (exc)
extra_innovation_inc acmailer_db to 1.2.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in acmailer allows a user to create a sub-account with administrative privileges due to incorrect authorization checks. This means unauthorized users could gain elevated access, potentially controlling the system or user data.

Detection Guidance

To detect this vulnerability, check the version of acmailer installed on your system. Compare it against the patched versions: CGI versions prior to 4.1.2 and DB versions prior to 1.2.2 are vulnerable. Use commands like 'acmailer --version' or check the version in the software's configuration files or web interface.

Impact Analysis

An attacker could exploit this to create admin-level sub-accounts, leading to unauthorized access, data theft, or system manipulation. This could compromise email delivery, user accounts, and sensitive information.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. Non-compliance risks legal penalties and reputational damage.

Mitigation Strategies

Update acmailer to version 4.1.2 (CGI) or later and acmailer DB to version 1.2.2 (DB) or later to address the incorrect authorization vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-70408. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart