envelope “Envelope-from” and “From” fields when sending
emails through OVH mail servers.
Due to OVH's default SPF configuration, which
commonly includes include:mx.ovh.com, any authenticated user with a
valid OVH email account can send messages that appear to originate from any
OVH-hosted domains using the default SPF record. Since the SPF policy
explicitly authorizes OVH mail servers (mx.ovh.com) to send mail on behalf of
these domains, forged messages successfully pass SPF validation despite
not being authorized by the impersonated domain owner.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Oct 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 07 Oct 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Authenticated users are able to manipulate both the SMTP envelope “Envelope-from” and “From” fields when sending emails through OVH mail servers. Due to OVH's default SPF configuration, which commonly includes include:mx.ovh.com, any authenticated user with a valid OVH email account can send messages that appear to originate from any OVH-hosted domains using the default SPF record. Since the SPF policy explicitly authorizes OVH mail servers (mx.ovh.com) to send mail on behalf of these domains, forged messages successfully pass SPF validation despite not being authorized by the impersonated domain owner. | |
| Title | Authenticated SMTP Sender Address Forgery | |
| Weaknesses | CWE-1188 CWE-290 CWE-346 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: ENISA
Published:
Updated: 2026-10-07T20:27:49.038Z
Reserved: 2026-03-23T12:53:47.473Z
Link: CVE-2026-33586
Updated: 2026-10-07T20:27:44.459Z
Status : Received
Published: 2026-10-07T16:17:47.643
Modified: 2026-10-07T21:17:16.040
Link: CVE-2026-33586
No data.
OpenCVE Enrichment
Updated: 2026-10-07T17:15:15Z
