Axigen Mail Server before 10.5.57 contains an improper...
Critical severity
Unreviewed
Published
Feb 5, 2026
to the GitHub Advisory Database
•
Updated Feb 13, 2026
Description
Published by the National Vulnerability Database
Feb 5, 2026
Published to the GitHub Advisory Database
Feb 5, 2026
Last updated
Feb 13, 2026
Axigen Mail Server before 10.5.57 contains an improper access control vulnerability in the WebAdmin interface. A delegated admin account with zero permissions can bypass access control checks and gain unauthorized access to the SSL Certificates management endpoint (page=sslcerts). This allows the attacker to view, download, upload, and delete SSL certificate files, despite lacking the necessary privileges to access the Security & Filtering section.
References