LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-1323

cps-it · mailqueue

Published
CVSS8.8
Severityhigh
WeaknessCWE-502
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

The extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker may exploit this to execute untrusted serialized code. Note that an active exploit requires write access to the directory configured at $GLOBALS['TYPO3_CONF_VARS']['MAIL']['transport_spool_filepath'].

References

← Back to the CVE Tracker

Our coverage of CVE-2026-1323

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-1323.