Exim 4.99.5 (CVE-2026-66140 / GCVE-25-2026-07-45-1) — any ETA?
Hi all,
It's been several days since the Exim team published EXIM-Security-2026-06-22.1
and released 4.99.5, fixing:
- GCVE-25-2026-07-45-1 (HIGH) — queue-name directory traversal, local
privilege escalation. Affects Exim 4.88 through 4.99.4.
- GCVE-25-2026-07-45-3 (MEDIUM) — .forward expansion when force_command
is set on a pipe transport.
Advisory: https://exim.org/static/doc/security/EXIM-Security-2026-06-22.1/EXIM-Security-2026-06-22.1.txt
I still don't see 4.99.5 shipped through the cPanel-provided Exim RPM, and I
can't find any official word here or in the change logs. Am I missing something?
My concern is specifically the shared-hosting threat model. This one only needs
local command-line access to exploit — which is exactly what any customer with
Terminal/SSH access has. On a multi-tenant cPanel box that turns a normal
unprivileged account into a local privesc vector. There is no config-level
workaround; the advisory says the only fix is upgrading to 4.99.5.
For now I've had to disable Terminal fleet-wide as a stopgap, which is not great
for customers who rely on it.
For comparison, the DirectAdmin side had this flagged and in motion the same day
the advisory dropped (community thread + CustomBuild picking up Exim security
releases quickly, as usual). I'd really like to see cPanel match that pace on a
HIGH-severity MTA issue.
Could someone from cPanel comment on:
1. Is a patched Exim build (4.99.5) already staged, and for which tiers/versions?
2. Expected ETA to STABLE / to the release tiers?
3. Any recommended interim mitigation beyond disabling shell access?
Running CloudLinux 8/9/10 on AlmaLinux here across a mixed fleet.
Thanks.
-
Hey there! Our team has case CPANEL-55071 open to work on this issue, and while we have a fix in place it's still being tested internally.
I can't say exactly when this will be released but hopefully this week or early next week.
0
Please sign in to leave a comment.
Comments
1 comment