PT-2026-6561 · Axigen · Axigen Mail Server

Published

2026-02-05

·

Updated

2026-02-05

·

CVE-2025-68722

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Axigen Mail Server versions prior to 10.5.57 Axigen Mail Server versions 10.6.0 through 10.6.25
Description The software contains a Cross-Site Request Forgery (CSRF) issue in the WebAdmin interface. This is due to improper handling of the s (breadcrumb) parameter. The application accepts state-changing requests via the GET method and automatically processes base64-encoded commands queued in the s parameter after administrator authentication. Attackers can create malicious URLs that, when clicked by administrators, execute arbitrary administrative actions upon login without further user interaction. These actions include creating rogue administrator accounts or modifying critical server configurations.
Recommendations Update Axigen Mail Server to version 10.5.57 or later. Update Axigen Mail Server to version 10.6.26 or later.

Exploit

Fix

XSS

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-68722

Affected Products

Axigen Mail Server