PT-2026-6561 · Axigen · Axigen Mail Server
Published
2026-02-05
·
Updated
2026-02-05
·
CVE-2025-68722
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Axigen Mail Server versions prior to 10.5.57
Axigen Mail Server versions 10.6.0 through 10.6.25
Description
The software contains a Cross-Site Request Forgery (CSRF) issue in the WebAdmin interface. This is due to improper handling of the
s (breadcrumb) parameter. The application accepts state-changing requests via the GET method and automatically processes base64-encoded commands queued in the s parameter after administrator authentication. Attackers can create malicious URLs that, when clicked by administrators, execute arbitrary administrative actions upon login without further user interaction. These actions include creating rogue administrator accounts or modifying critical server configurations.Recommendations
Update Axigen Mail Server to version 10.5.57 or later.
Update Axigen Mail Server to version 10.6.26 or later.
Exploit
Fix
XSS
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Axigen Mail Server