CVE-2026-1323: Cps-It Mailqueue
High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.
The extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker may exploit this to execute untrusted serialized code. Note that an active exploit requires write access to the directory configured at $GLOBALS['TYPO3_CONF_VARS']['MAIL']['transport_spool_filepath'].
Affected products
- Cps-It Mailqueue: before 0.4.5 (fixed in 0.4.5); from 0.5.0, before 0.5.2 (fixed in 0.5.2)
Published 2026-03-17. Last modified 2026-06-17.