CVE-2026-27602

Modoboa is a mail hosting and management platform. Prior to version 2.7.1, `exec_cmd()` in `modoboa/lib/sysutils.py` always runs subprocess calls with `shell=True`. Since domain names flow directly into shell command strings without any sanitization, a Reseller or SuperAdmin can include shell metacharacters in a domain name to run arbitrary OS commands on the server. Version 2.7.1 patches the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:modoboa:modoboa:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:27

Type Values Removed Values Added
Summary
  • (es) Modoboa es una plataforma de alojamiento y gestión de correo. Antes de la versión 2.7.1, `exec_cmd()` en `modoboa/lib/sysutils.py` siempre ejecuta llamadas a subprocesos con `shell=True`. Dado que los nombres de dominio fluyen directamente a las cadenas de comandos de shell sin ninguna sanitización, un Revendedor o SuperAdministrador puede incluir metacaracteres de shell en un nombre de dominio para ejecutar comandos arbitrarios del sistema operativo en el servidor. La versión 2.7.1 corrige el problema.

26 Mar 2026, 16:30

Type Values Removed Values Added
First Time Modoboa
Modoboa modoboa
CPE cpe:2.3:a:modoboa:modoboa:*:*:*:*:*:*:*:*
References () https://github.com/modoboa/modoboa/commit/27a7aa133d3608fe8c25ae39125d1012c333cbfa - () https://github.com/modoboa/modoboa/commit/27a7aa133d3608fe8c25ae39125d1012c333cbfa - Patch
References () https://github.com/modoboa/modoboa/releases/tag/2.7.1 - () https://github.com/modoboa/modoboa/releases/tag/2.7.1 - Product, Release Notes
References () https://github.com/modoboa/modoboa/security/advisories/GHSA-wwv8-cqpr-vx3m - () https://github.com/modoboa/modoboa/security/advisories/GHSA-wwv8-cqpr-vx3m - Exploit, Vendor Advisory

26 Mar 2026, 16:16

Type Values Removed Values Added
References () https://github.com/modoboa/modoboa/security/advisories/GHSA-wwv8-cqpr-vx3m - () https://github.com/modoboa/modoboa/security/advisories/GHSA-wwv8-cqpr-vx3m -

25 Mar 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-25 19:16

Updated : 2026-06-17 10:27


NVD link : CVE-2026-27602

Mitre link : CVE-2026-27602

CVE.ORG link : CVE-2026-27602


JSON object : View

Products Affected

modoboa

  • modoboa
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')