Published:2026/08/19  Last Updated:2026/08/19

JVN#47716829
Multiple vulnerabilities in acmailer

Overview

acmailer provided by Extra Innovation Inc. contains multiple vulnerabilities.

Products Affected

  • acmailer CGI versions prior to ver.4.1.2
  • acmailer DB versions prior to ver.1.2.2

Description

acmailer provided by Extra Innovation Inc. contains multiple vulnerabilities listed below:

  • Cross-site Scripting (CWE-79)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N Base Score 5.1
    • CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Base Score 6.1
    • CVE-2026-66358
  • Incorrect Authorization (CWE-863)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 8.7
    • CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Base Score 8.8
    • CVE-2026-70408

Impact

  • An arbitrary script may be executed in the web browser of the user (CVE-2026-66358).
  • A sub-account user could create another sub-account that has administrative privileges (CVE-2026-70408).

Solution

Update the Software
Update the software to the latest version according to the information provided by the developer.

Vendor Status

Vendor Link
Extra Innovation Inc. acmailer (Text in Japanese)

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

CVE-2026-66358
Yuji Tounai of Mitsui Bussan Secure Directions, Inc. and Fumiya Funakoshi reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

CVE-2026-70408
Fumiya Funakoshi reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2026-66358
CVE-2026-70408
JVN iPedia JVNDB-2026-000118