CVE-2023-26986: Chinamobileltd Oa Mailbox Pc

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

An issue in China Mobile OA Mailbox PC v2.9.23 allows remote attackers to execute arbitrary commands on a victim host via user interaction with a crafted EML file sent to their OA mailbox.

Affected products

Published 2023-04-10. Last modified 2026-06-17.