High severity8.8NVD Advisory· Published Jul 11, 2022· Updated Jun 17, 2026
CVE-2022-31138
CVE-2022-31138
Description
mailcow is a mailserver suite. Prior to mailcow-dockerized version 2022-06a, an extended privilege vulnerability can be exploited by manipulating the custom parameters regexmess, skipmess, regexflag, delete2foldersonly, delete2foldersbutnot, regextrans2, pipemess, or maxlinelengthcmd to execute arbitrary code. Users should update their mailcow instances with the update.sh script in the mailcow root directory to 2022-06a or newer to receive a patch for this issue. As a temporary workaround, the Syncjob ACL can be removed from all mailbox users, preventing changes to those settings.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<2022-06a+ 1 more
- (no CPE)range: <2022-06a
- (no CPE)range: < 2022-06a
Patches
Vulnerability mechanics
References
3- github.com/mailcow/mailcow-dockerized/commit/d373164e13a14e058f82c9f1918a5612f375a9f9nvdPatchThird Party Advisory
- github.com/mailcow/mailcow-dockerized/releases/tag/2022-06anvdRelease NotesThird Party Advisory
- github.com/mailcow/mailcow-dockerized/security/advisories/GHSA-vx9w-h33p-5vhcnvdMitigationThird Party Advisory
News mentions
0No linked articles in our index yet.