← Back to search

CVE-2026-94184

8.1 HIGH

Published 2026-09-21 · Updated 2026-09-22

AI risk analysis

Summary
The flaw is a stack-based buffer overflow in fetchmail when NTLM support is enabled, allowing a malicious server to potentially execute arbitrary code or cause service disruption.
Exploitability
Exploitation requires a compromised or malicious mail server advertising NTLM authentication and sending a crafted challenge; this is moderately difficult given the need for specific conditions.
Blast radius
If exploited, the impact could be severe, leading to remote code execution on affected systems, potentially compromising the entire network.
Prioritized remediation
Update fetchmail to versions later than v6.6.7 or disable NTLM support if not needed.
rceauth-bypassnetwork

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious or compromised mail server advertising NTLM authentication can send a crafted Type 2 challenge that causes fetchmail to write past a fixed stack buffer while building the NTLM authenticate response. This may lead to remote code execution depending on stack-frame layout, or to authentication failure or process termination under memory hardening. Affects v5.0.8 through v6.6.6.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-121

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.