A second-order SQL injection vulnerability tracked as CVE-2026-40871 affects mailcow-dockerized through the Mailcow API's quarantine_category field. The flaw originates in the /api/v1/add/mailbox endpoint, which stores attacker-controlled input without validation or sanitization; that value is later processed by quarantine_notify.py, where SQL queries are constructed with unsafe Python % string formatting instead of parameterized statements. Because the payload is written first and executed only when the quarantine notification job runs, the issue is a delayed second-order injection rather than an immediate SQL injection at the API endpoint.
The disclosed impact includes arbitrary SQL execution, UNION SELECT-based data exfiltration, and exposure of sensitive internal information in quarantine notification emails, including administrator credentials. The advisory warns that an attacker with Mailcow API access could use the bug to retrieve internal data and potentially pivot toward broader system compromise. A documented attack chain also describes combining an XSS flaw in SOGo to steal an API key, then using that access to plant the SQL payload and leak credentials through the quarantine email workflow.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A GitHub-hosted vulnerability disclosure for CVE-2026-40871 was published, documenting the same Mailcow second-order SQL injection issue. This appears to be a separate publication of the vulnerability rather than a new incident development.
A security advisory disclosed a second-order SQL injection vulnerability in Mailcow's API quarantine_category handling, where unsanitized input stored via /api/v1/add/mailbox is later executed by quarantine_notify.py using unsafe SQL string formatting. The advisory said the flaw could enable arbitrary SQL execution, data exfiltration, leakage of administrator credentials in quarantine emails, and possible further compromise by an attacker with API access.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.