CVE-2026-40193 is an LDAP injection vulnerability affecting Maddy mail server versions prior to 0.9.3. The flaw exists in the auth.ldap module where user-supplied usernames are interpolated directly into LDAP search filters and DN strings without proper escaping, despite the necessary sanitization function being available in the codebase. This allows attackers to inject arbitrary LDAP filter expressions through the username field in AUTH PLAIN or LOGIN commands over SMTP submission or IMAP interfaces. The vulnerability carries a CVSS v3.1 score of 8.2 (HIGH) with a network-based attack vector requiring no authentication or user interaction. The attack complexity is low, indicating straightforward exploitation. The primary impact is high confidentiality loss through LDAP directory enumeration and blind attribute extraction, with limited integrity compromise via identity spoofing. The EPSS score of 0.00046 suggests exploitation probability remains relatively low within the broader CVE ecosystem. This vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog and shows no signs of active exploitation in the wild. There is no indication of publicly available exploit code, and community attention remains minimal based on the inactive Hot List status. The patched version 0.9.3 is available, and organizations running affected versions should prioritize updating to remediate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.9.3CPE matchmatch criteria | cpe:2.3:a:maddy_project:maddy:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.