Jump to the main content block

【Security Advisory】Huanki Technology | C Cm@il - Missing Authentication Vulnerability

publish date : 2026-02-24 update date : 2026-02-24

Source: Ministry of education information & communication security contingency platform

"" "" ""

Publication Number TACERT-ANA-2026021108020303 Publication Time 2026/02/11 08:41
Incident Type ANA-Vulnerability Alert Discovery Time 2026/02/11 08:41
Impact Level Low  
[Subject]
【Security Advisory】Huanki Technology | C Cm@il - Missing Authentication Vulnerability
[Content]
Forwarded from TWCERTCC-200-202602-00000006

【Huanki Technology | C Cm@il - Missing Authentication】(CVE-2026-2234, CVSS: 9.1) An unauthenticated remote attacker may read and modify any user's email content.

(Information Sharing Level: WHITE (Information content can be publicly disclosed)
[Affected Platform]
C Cm@il package olln-base versions prior to 7.0-978 (not including 7.0-978)
[Recommended Actions]
Update the olln-base package to version 7.0-978 (including 7.0-978) or later.
[Reference]
https://www.twcert.org.tw/tw/cp-132-10703-3d02f-1.html
(This notification is for informational purposes only and does not constitute a cybersecurity incident).
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw
Organizer: Computer Center
Click Num: