External risk intelligence

Mailu Authentication Bypass via Trusted Header Spoofing

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-85751

Mailu is a mail server, a service designed to be internet-facing by default to send and receive email. Because it operates as an edge-facing service that must be reachable from the public internet to function, this vulnerability in the authentication mechanism affects a component that is inherently exposed to external traffic.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in Mailu, an email server solution. The issue allows unauthenticated remote attackers to bypass authentication by spoofing a trusted proxy identity. This could potentially lead to unauthorized access to email server functionalities. The main concern is confirming if Mailu is deployed and if this specific authentication bypass configuration is in use.

  • Authentication bypass possible in Mailu email servers.
  • Attackers can impersonate trusted proxies remotely.
  • Confirm Mailu deployment and proxy configuration relevance.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending a specially crafted request to a Mailu mail server. If the server is configured with `PROXY_AUTH_WHITELIST` but not `REAL_IP_HEADER`, the attacker can spoof a trusted proxy's identity by controlling the `X-Forwarded-By` header. This bypasses authentication, allowing the attacker to gain unauthorized access.

  • Server exposed to the internet.
  • Spoofed `X-Forwarded-By` header.
  • Unauthenticated remote access.

Live Threat

Current exploitation, exposure, and threat context

When Mailu is deployed with specific proxy configurations, an unauthenticated remote attacker could impersonate a trusted proxy. This could allow them to bypass authentication mechanisms, potentially affecting the confidentiality and integrity of the mail server's operations and data.

  • Mail server authentication.
  • Spoofing proxy identity to bypass checks.
  • Unauthorized access to mail server functions.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Mailu, a Docker-based mail server, impacts deployments using `PROXY_AUTH_WHITELIST` without `REAL_IP_HEADER` configured. The first practical step is to identify all Mailu instances, determine their reachability and business criticality, and locate the accountable owner before planning remediation.

  • Platform or application owners should manage the fix.
  • Verify `PROXY_AUTH_WHITELIST` and `REAL_IP_HEADER` settings.
  • Plan upgrades during the next maintenance window.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Mailu and how is it structured?

Mailu is a complete, containerized mail server solution that utilizes Docker images to provide essential email services like SMTP and IMAP. By bundling these components into a unified framework, it enables administrators to deploy a self-hosted email infrastructure.

How does this flaw bypass authentication?

This vulnerability involves CWE-290 and CWE-807, where the server incorrectly trusts client-supplied headers. By manipulating the X-Forwarded-By header, an attacker can impersonate a trusted proxy identity, effectively bypassing the server's authentication checks.

What specific configurations trigger this issue?

The flaw impacts Mailu deployments where PROXY_AUTH_WHITELIST is enabled but the REAL_IP_HEADER directive remains unset. This scope does not include correctly configured systems; it specifically affects instances where the proxy identity logic relies on unverified headers.

Why is this server flaw considered highly relevant?

Because Mailu is an edge-facing service designed to be reachable from the internet, Halo Surface Signal confirms it is very likely to be affected. The inherent exposure of a public-facing mail server increases the risk of this authentication bypass.

How should administrators remediate this vulnerability?

Operators must first identify all Mailu deployments and verify their proxy settings. The primary fix requires updating to Mailu version 2024.06.55 or using Mailu helm-charts 2.7.3 or later, which resolve the header handling vulnerability.

References