Froxlor · Froxlor · CVE-2026-100718
**Name of the Vulnerable Software and Affected Versions**
Froxlor versions prior to 2.3.12
**Description**
The software fails to enforce the `mail.allow external domains` policy within the 'EmailSender.add' API endpoint. When an administrator enables the allowed-sender feature but disables external allowed-sender domains (setting `mail.enable allow sender` to 1 and `mail.allow external domains` to 0), an authenticated customer with API access can use the 'EmailSender.add' endpoint to register an arbitrary external sender address. This bypasses the administrator configuration and allows customers to authorize sender identities outside their hosted domains, which can facilitate sender spoofing.
**Recommendations**
Update to version 2.3.12 or later.