PT-2026-102417 · Opendmarc · Opendmarc
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
OpenDMARC versions prior to 1.4.3
Description
A remote authentication bypass via spoofing is possible in the Multi-Record Set Handler component. The issue resides in the
opendmarc policy query dmarc() function.Recommendations
Update to a version newer than 1.4.2.
As a temporary workaround, restrict the use of the
opendmarc policy query dmarc() function.Exploit
Fix
Improper Authentication
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Opendmarc