OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-100718

HIGH · CVSS 7.1 EPSS 0.19% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

Froxlor versions up to 2.3.10 are vulnerable due to a failure to enforce the mail.allow_external_domains policy in the EmailSender.add API command, allowing authenticated users to register arbitrary external sender addresses despite administrative restrictions. This vulnerability can lead to sender spoofing, undermining email security and potentially facilitating phishing attacks. Organizations using Froxlor for email management should prioritize updating to version 2.3.12 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100718
Severity
HIGH
CVSS
7.1
EPSS
0.19%

Original NVD Description

Froxlor through 2.3.10 does not enforce the mail.allow_external_domains policy in the EmailSender.add API command. When an administrator has enabled the allowed-sender feature but disabled external allowed-sender domains (mail.enable_allow_sender = 1, mail.allow_external_domains = 0), an authenticated customer with API access can still use EmailSender.add to register an arbitrary external sender address for their mailbox, which is stored despite the policy. This creates a bypass between the UI/administrator configuration and the API, and — where the generated mail configuration consumes the allowed-sender table — allows a customer to authorize sender identities outside their hosted domains, facilitating sender spoofing. Fixed in 2.3.12.