Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection.
No PoCs from references.
- https://github.com/0xMarcio/cve
- https://github.com/ARPSyndicate/cve-scores
- https://github.com/GhostTroops/TOP
- https://github.com/OscarBataille/CVE-2025-26794
- https://github.com/defHawk-tech/CVEs
- https://github.com/exfil0/SMTP-Hunter
- https://github.com/fkie-cad/nvd-json-data-feeds
- https://github.com/ishwardeepp/CVE-2025-26794-Exim-Mail-SQLi
- https://github.com/nomi-sec/PoC-in-GitHub
- https://github.com/plzheheplztrying/cve_monitor