PT-2026-39715 · Elie222 · Inbox-Zero

Published

2026-05-11

·

Updated

2026-05-11

·

CVE-2026-42865

CVSS v4.0

2.3

Low

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Inbox Zero is an AI personal assistant for email. Prior to 2.29.3, the cleaner email stream endpoint used a shared Redis subscription listener, which could deliver thread events for one authenticated account to another authenticated account using the cleaner feature at the same time. This vulnerability is fixed in 2.29.3.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2026-42865

Affected Products

Inbox-Zero