Exim Directory Traversal Vulnerability Exposes Files Outside the Mail Spool
A newly disclosed vulnerability in Exim, one of the most widely deployed mail transfer agents (MTAs) on Unix-like systems, allows local attackers to escalate privileges by accessing files outside the

A newly disclosed vulnerability in Exim, one of the most widely deployed mail transfer agents (MTAs) on Unix-like systems, allows local attackers to escalate privileges by accessing files outside the intended mail spool directory. Tracked as EXIM-Security-2026-06-22.1 (GCVE-25-2026-07-45-1), the flaw carries a High severity rating and affects a massive swath of Exim deployments spanning nearly […] The post Exim Directory Traversal Vulnerability Exposes Files Outside the Mail Spool appeared first on Cyber Security News.
A newly disclosed vulnerability in Exim, one of the most widely deployed mail transfer agents (MTAs) on Unix-like systems, allows local attackers to escalate privileges by accessing files outside the intended mail spool directory. Tracked as EXIM-Security-2026-06-22.1 (GCVE-25-2026-07-45-1), the flaw carries a High severity rating and affects a massive swath of Exim deployments spanning nearly a decade of releases. The vulnerability stems from improper handling of command-line arguments used to transfer queue names during Exim’s execution chain. Exim Directory Traversal Vulnerability By manipulating these arguments, a local attacker with command-line access can perform a directory traversal attack, reaching files well outside the spool area that Exim normally restricts itself to. Because Exim often runs with elevated privileges to manage mail queues, this traversal can be leveraged for local privilege escalation, potentially granting an attacker access to sensitive system files or higher-level permissions. Exploitation requires local, command-line access to the target system, which limits remote attack surface but makes this a significant concern in multi-user environments, shared hosting platforms, and systems where untrusted users have shell access. Affected Versions The flaw impacts an unusually broad range of releases: All Exim versions from 4.88 (released 2017) through 4.99.4 The development (master) branch was also vulnerable Nearly nine years of production releases are affected Given Exim’s role as a default MTA on countless Linux distributions, the scope of potentially exposed systems is substantial. The only effective remediation is upgrading to Exim version 4.99.5. The Exim fix addresses the issue by restricting the use of the vulnerable command-line options to already privileged users and limiting the characters that may be used for queue names, effectively closing the traversal vector. Mitigation Upgrade immediately to Exim 4.99.5, available from ftp.exim.org and the official Exim Git repository. Audit systems for unauthorized local users or shell access that could serve as an exploitation vector prior to patching. Organizations running mail infrastructure on affected Exim versions should treat this as an urgent patching priority, particularly on multi-tenant or shared systems where local access controls may already be weaker. Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN. The post Exim Directory Traversal Vulnerability Exposes Files Outside the Mail Spool appeared first on Cyber Security News.
Join the Discussion
Comments coming soon. Follow us on social media for real-time discussions.


