# CVE-2022-39258

## Summary

- **CVE ID:** CVE-2022-39258
- **Severity:** HIGH
- **CVSS Score:** 8.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N)
- **CWE:** CWE-451, CWE-200
- **Published:** Sep 27, 2022
- **Last Modified:** Mar 13, 2026

## Description

mailcow is a mailserver suite. A vulnerability innversions prior to 2022-09 allows an attacker to craft a custom Swagger API template to spoof Authorize links. This could redirect a victim to an attacker controller place to steal Swagger authorization credentials or create a phishing page to steal other information. The issue has been fixed with the 2022-09 mailcow Mootember Update. As a workaround, one may delete the Swapper API Documentation from their e-mail server.

## Affected Products

- mailcow — mailcow-dockerized (< 2022-09)

## References

- [CNA](https://github.com/mailcow/mailcow-dockerized/security/advisories/GHSA-vjgf-cp5p-wm45)
- [CNA](https://github.com/mailcow/mailcow-dockerized/pull/4766)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.26%
- **EPSS Percentile:** 48.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._