Collax Security Gateway: OS command injection in the held-mail queue release path lets a delegated mailadmin run commands as root
A delegated mail administrator scoped to held-mail management overwrites the client-side queue id and obtains arbitrary command execution as admin and then root.
Advisory ID: TP-2026-067
Product: Collax Security Gateway (German UTM, firewall, mail and SSL-VPN appliance; also affects Collax Business Server and Groupware Suite)
Vulnerability type: OS command injection (CWE-78)
CVE: pending (MITRE CNA-LR)
CVSS 3.1: 8.5 (High) · CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Vendor advisory: Collax release notes CSG 7.2.48
Affected versions: 7.2.46 and earlier
Fixed in: 7.2.48
Reported: 01 September 2026
Summary
The admin interface supports delegated administration: a user granted only the mailadmin role may open the held-mail form (forms/mailqhold.form:4). Each queue row exposes a
Root cause
releaseMails joins the id of every marked row into $release and interpolates it into a double-quoted shell command, system qq[/usr/sbin/suwrap root postfix_queue multiple-release "$release" >/dev/null] (AKLib/Mail/MailQHold.pm:112); removeMails (:123) and sendMails (:134) repeat the pattern.
The value was meant to be a space-joined list of Postfix queue ids, not a shell fragment.
The row id is client-overwritable: the form ships
The form is granted to any holder of role.mailadmin (forms/mailqhold.form:4), a role below full administrator.
The injected shell runs as OS user admin (adminhttpd.conf:119-120), and /usr/sbin/suwrap is setuid root:admin mode 4750, so admin reaches root directly.
Proof of Concept
Schematically: sign in to :8001 as a user holding only role.mailadmin, open the held-mail form (/json/
{"method":"releaseMails","params":[{"id":"<shell breakout>","mark":1}]}
releaseMails joins the marked row id into $release and executes the shell command, before postfix_queue. Verified on 2026-09-01 with a uid=0(root) marker under chroot+akrun.
Impact
- A delegated mail administrator scoped to held-mail management runs arbitrary OS commands as admin and then root.
- Requires at least one held mail so an overwritable row exists; the score rises to 9.9 where the attacker can induce a held mail.
- Full compromise of the gateway from a limited delegated credential, a privilege-boundary break.
- No CSP, X-Frame-Options or X-Content-Type-Options header anywhere on the appliance.
References
Is Something Like This in Your Software?
Our team found this vulnerability during its work. Have your applications tested by the same specialists, with a penetration test from turingpoint.
