{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-33586", "assignerOrgId": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158", "state": "PUBLISHED", "assignerShortName": "ENISA", "dateReserved": "2026-03-23T12:53:47.473Z", "datePublished": "2026-10-07T15:00:14.278Z", "dateUpdated": "2026-10-07T20:27:49.038Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158", "shortName": "ENISA", "dateUpdated": "2026-10-07T15:00:14.278Z" }, "title": "Authenticated SMTP Sender Address Forgery", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-1188", "description": "CWE-1188 Initialization of a resource with an insecure default", "type": "CWE" } ] }, { "descriptions": [ { "lang": "en", "cweId": "CWE-346", "description": "CWE-346: Origin Validation Error", "type": "CWE" } ] }, { "descriptions": [ { "lang": "en", "cweId": "CWE-290", "description": "CWE-290 Authentication bypass by spoofing", "type": "CWE" } ] } ], "affected": [ { "vendor": "OVHcloud", "product": "OVHcloud", "versions": [ { "status": "affected", "version": "0", "lessThan": "2026-07-20", "versionType": "date" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "Authenticated users are able to manipulate both the SMTP\nenvelope “Envelope-from” and “From” fields when sending\nemails through OVH mail servers.\n\n\n\nDue to OVH's default SPF configuration, which\ncommonly includes include:mx.ovh.com, any authenticated user with a\nvalid OVH email account can send messages that appear to originate from any\nOVH-hosted domains using the default SPF record. Since the SPF policy\nexplicitly authorizes OVH mail servers (mx.ovh.com) to send mail on behalf of\nthese domains, forged messages successfully pass SPF validation despite\nnot being authorized by the impersonated domain owner.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "

Authenticated users are able to manipulate both the SMTP\nenvelope “Envelope-from” and “From” fields when sending\nemails through OVH mail servers.

Due to OVH's default SPF configuration, which\ncommonly includes include:mx.ovh.com, any authenticated user with a\nvalid OVH email account can send messages that appear to originate from any\nOVH-hosted domains using the default SPF record. Since the SPF policy\nexplicitly authorizes OVH mail servers (mx.ovh.com) to send mail on behalf of\nthese domains, forged messages successfully pass SPF validation despite\nnot being authorized by the impersonated domain owner.


" } ] } ], "references": [ { "url": "https://docs.ovhcloud.com/en/guides/web-cloud/email-and-collaborative-solutions/troubleshooting/email-rejected-cross-domain-spoofing" } ], "metrics": [ { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV4_0": { "attackVector": "NETWORK", "attackComplexity": "LOW", "attackRequirements": "NONE", "privilegesRequired": "LOW", "userInteraction": "NONE", "vulnConfidentialityImpact": "NONE", "subConfidentialityImpact": "NONE", "vulnIntegrityImpact": "NONE", "subIntegrityImpact": "HIGH", "vulnAvailabilityImpact": "NONE", "subAvailabilityImpact": "NONE", "exploitMaturity": "ATTACKED", "Safety": "NOT_DEFINED", "Automatable": "NOT_DEFINED", "Recovery": "NOT_DEFINED", "valueDensity": "NOT_DEFINED", "vulnerabilityResponseEffort": "NOT_DEFINED", "providerUrgency": "NOT_DEFINED", "version": "4.0", "baseSeverity": "MEDIUM", "baseScore": 6.3, "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N/E:A" } } ], "credits": [ { "lang": "en", "value": "Abdullah HAMED of ENGIE IT Offensive Cybersecurity Team", "type": "finder" } ], "source": { "discovery": "UNKNOWN" }, "x_generator": { "engine": "Vulnogram 1.0.5" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-10-07T20:27:35.754415Z", "id": "CVE-2026-33586", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-10-07T20:27:49.038Z" } } ] } }