envelope “Envelope-from” and “From” fields when sending
emails through OVH mail servers.
Due to OVH's default SPF configuration, which
commonly includes include:mx.ovh.com, any authenticated user with a
valid OVH email account can send messages that appear to originate from any
OVH-hosted domains using the default SPF record. Since the SPF policy
explicitly authorizes OVH mail servers (mx.ovh.com) to send mail on behalf of
these domains, forged messages successfully pass SPF validation despite
not being authorized by the impersonated domain owner.
Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 07 Oct 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 07 Oct 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Authenticated users are able to manipulate both the SMTP envelope “Envelope-from” and “From” fields when sending emails through OVH mail servers. Due to OVH's default SPF configuration, which commonly includes include:mx.ovh.com, any authenticated user with a valid OVH email account can send messages that appear to originate from any OVH-hosted domains using the default SPF record. Since the SPF policy explicitly authorizes OVH mail servers (mx.ovh.com) to send mail on behalf of these domains, forged messages successfully pass SPF validation despite not being authorized by the impersonated domain owner. | |
| Title | Authenticated SMTP Sender Address Forgery | |
| Weaknesses | CWE-1188 CWE-290 CWE-346 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ENISA
Published:
Updated: 2026-10-07T20:27:49.038Z
Reserved: 2026-03-23T12:53:47.473Z
Link: CVE-2026-33586
Updated: 2026-10-07T20:27:44.459Z
Status : Received
Published: 2026-10-07T16:17:47.643
Modified: 2026-10-07T21:17:16.040
Link: CVE-2026-33586
No data.
OpenCVE Enrichment
Updated: 2026-10-07T17:15:15Z