Collax Security Gateway: OS command injection in Postfix queue hold lets a delegated mailadmin run commands as root

A delegated mail administrator scoped to mail-queue management obtains, with no precondition, arbitrary command execution as admin and then root through the unvalidated refvalue of the hold action.

Advisory ID: TP-2026-071
Product: Collax Security Gateway (German UTM, firewall, mail and SSL-VPN appliance; also affects Collax Business Server and Groupware Suite)
Vulnerability type: OS command injection (CWE-78)
CVE: pending (MITRE CNA-LR)
CVSS 3.1: 9.9 (Critical) · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vendor advisory: Collax release notes CSG 7.2.48
Affected versions: 7.2.46 and earlier
Fixed in: 7.2.48
Reported: 01 September 2026

Summary

The admin interface supports delegated administration: a user granted only the mailadmin role may open the mail-queue form (forms/mailqueue.form:5). The form's hold action is declared function='holdMail' refvalue='id' (forms/mailqueue.form:63). The JSON-RPC dispatcher forwards the client-supplied refvalue unchanged into holdMail, which concatenates it into a shell string, system '/usr/sbin/suwrap root postfix_queue hold ' . $key . ' >/dev/null' (AKLib/Mail/MailQueue.pm:85). The inbound refvalue receives no type or format validation; the request handler passes the raw JSON field straight to the method. Because suwrap is setuid root:admin mode 4750, admin escalates to root in one hop, with no precondition on queue state.

Root cause

holdMail concatenates its argument into a shell command, system '/usr/sbin/suwrap root postfix_queue hold ' . $key . ' >/dev/null' (AKLib/Mail/MailQueue.pm:85), so shell metacharacters in $key execute.
The value was meant to be a Postfix queue id: the postfix_queue helper documents 'qid is a postfix queue id' and even single-quotes its own argument as -h '$2' (suwrap/postfix_queue:9,31), so the injection is a hop-1 defect in the Perl caller before the helper's own quoting.
The hold action supplies refvalue='id' (forms/mailqueue.form:63), and the request handler passes the raw client JSON refvalue to the method with no inbound validation (its actionCheck builds only outbound links).
The form is granted to any holder of role.mailadmin (forms/mailqueue.form:5), a role below full administrator.
The injected shell runs as OS user admin (adminhttpd.conf:119-120), and /usr/sbin/suwrap is setuid root:admin mode 4750, so admin reaches root directly.

Proof of Concept

Schematically: sign in to :8001 as a user holding only role.mailadmin and open the mail-queue form (/json//mailqueue).

{"method":"holdMail","refvalue":"<shell breakout>","params":[]}

holdMail interpolates refvalue into the shell string and executes it before postfix_queue. There is no precondition on queue contents. Verified on 2026-09-01 with a uid=0(root) marker under chroot+akrun.

Impact

  • A delegated mail administrator scoped to mail-queue management runs arbitrary OS commands as admin and then root.
  • No precondition on queue contents; the single hold action reaches the sink.
  • Full compromise of the gateway from a limited delegated credential, a privilege-boundary break.
  • No CSP, X-Frame-Options or X-Content-Type-Options header anywhere on the appliance.

References

Is Something Like This in Your Software?

Our team found this vulnerability during its work. Have your applications tested by the same specialists, with a penetration test from turingpoint.