PT-2026-99389 · Froxlor · Froxlor

·

CVE-2026-100718

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Froxlor versions prior to 2.3.12
Description The software fails to enforce the mail.allow external domains policy within the 'EmailSender.add' API endpoint. When an administrator enables the allowed-sender feature but disables external allowed-sender domains (setting mail.enable allow sender to 1 and mail.allow external domains to 0), an authenticated customer with API access can use the 'EmailSender.add' endpoint to register an arbitrary external sender address. This bypasses the administrator configuration and allows customers to authorize sender identities outside their hosted domains, which can facilitate sender spoofing.
Recommendations Update to version 2.3.12 or later.

Exploit

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100718
GHSA-M9J6-9856-68XF

Affected Products

Froxlor