| Publishing Date | 09.06.2026 |
|---|---|
| Last Update | 09.06.2026 |
| Tracking ID | IBA-2026-10 |
CVE IDs of the affected library
- CVE-2026-41319
- CVE-2026-30227
Summary
The implemented third-party dependencies MimeKit and MailKit contained two vulnerabilities affecting email communication. A CRLF injection flaw in MimeKit (CVE-2026-30227) could allow SMTP command or mail header injection when attacker-influenced input is passed into a mailbox address, and a STARTTLS response injection flaw in MailKit (CVE-2026-41319) could allow a Man-in-the-Middle attacker to downgrade SASL authentication and potentially expose credentials during the plaintext-to-TLS upgrade. No active exploitation of these vulnerabilities is known within the product.
Affected products
This applies to all iba products up to the versions listed below:
- ibaHD-Server v3.6.1
How do I know that I’m affected?
If you have installed any of the products listed above in a version at or below the one indicated, you are affected.
Solution
With the following versions, the issue has been fixed:
- ibaHD-Server v3.6.2
Customer Actions
Please install the update as described in the Solution section.
Timeline
| 2026-05-19 | Noted by the Security Team. |
| 2026-06-09 | Solution implemented in ibaHD-Server v3.6.2 |
