CVE-2026-94184: some builds of fetchmail 6.6.6 and older vulnerable to remote code execution in NTLM authentication client (revised fetchmail-SA-2026-01)
Some fetchmail 6.6.6 and older builds may allow RCE via an NTLM stack overflow.
Matthias Andree revised fetchmail-SA-2026-01, tracked as CVE-2026-94184. Some builds of fetchmail 6.6.6 and older compiled with NTLM support can suffer a stack buffer overflow in the NTLM authentication client. A rogue server could potentially gain remote code execution, depending on the compiler, ABI, calling conventions, and build flags. The advisory was first announced on 2026-06-27 and revised on 2026-09-22 as version 1.2.
- CVE-2026-94184 affects some fetchmail 6.6.6 and older builds.
- A stack buffer overflow is in the NTLM authentication client.
- Code execution depends on --enable-NTLM, compiler, ABI, and flags.
- fetchmail-SA-2026-01 was revised to version 1.2 on 2026-09-22.
Vulnerabilities mentionedAll →
- CVE-2026-941848.1—Stack Buffer Overflow in fetchmail NTLM Handling Enables Remote Code Executionpublished · The fetchmail Project fetchmail
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-94184 | Stack Buffer Overflow in fetchmail NTLM Handling Enables Remote Code Execution fetchmail, when compiled with NTLM support, contains a stack-based buffer overflow (CWE-121) in the code that constructs the NTLM authenticate response while parsing a server-supplied Type 2 challenge. A malicious or compromised POP3/IMAP mail server that advertises NTLM authentication can trigger the overflow during the authentication handshake, writing past a fixed stack buffer before any mail is transferred. Depending on stack-frame layout, this can yield remote code execution in the fetchmail process; on memory-hardened builds it more likely causes authentication failure or a crash (denial of polling). The CVSS 3.1 score is 8.1 (high) with network vector and no privileges or user interaction required, though attack complexity is high because the attacker must control or have compromised the mail server that fetchmail polls. There is no public proof of concept, the flaw is not in the CISA KEV catalog, and no exploitation has been observed in the wild. |
Posted by Matthias Andree on Sep 22 fetchmail-SA-2026-01: --enable-NTLM potential remote code execution Topics: Possible remote code execution from a rogue server through stack buffer overflow in NTLM authentication method, depending on build details including compiler, ABI, call conventions, and compiler flags. Author: Matthias Andree Version: 1.2 Announced: 2026-06-27, revised 2026-09-22 Type:...
This source does not provide full text. Read it at seclists.org.