关键漏洞信息 TVN ID: TVN-202602004 CVE ID: CVE-2026-2234, CVE-2026-2235, CVE-2026-2236 CVSS CVE-2026-2234 (Critical): 9.1 / AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVE-2026-2235 (Medium): 6.5 / AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVE-2026-2236 (High): 7.5 / AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products C&Cm@il package olln-base version before 7.0-978 Description CVE-2026-2234 (Missing Authentication): Unauthenticated remote attackers can read and modify any user's mail content. CVE-2026-2235 (SQL Injection): Authenticated remote attackers can inject arbitrary SQL commands to read database contents. CVE-2026-2236 (SQL Injection): Unauthenticated remote attackers can inject arbitrary SQL commands to read database contents. Solution Update package olln-base to version 7.0-978 or later. Credit Linwz(DEVCORE) Public Date 2026-02-09