SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-90936

MEDIUM · CVSS 4.3 Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Froxlor versions prior to 2.3.7 are vulnerable due to improper scoping of sender alias lookups, allowing authenticated attackers to enumerate global sender alias IDs and access other customers' allowed sender values through manipulated delete confirmation requests. This could lead to unauthorized information disclosure, potentially compromising customer data. Service providers and administrators using Froxlor should prioritize updating to the latest version to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-90936
Severity
MEDIUM
CVSS
4.3
EPSS
N/A

Original NVD Description

Froxlor before 2.3.7 fails to properly scope sender alias lookups to the current customer in customer_email.php. Authenticated attackers can enumerate global sender alias IDs and read other customers' allowed sender values by supplying arbitrary senderid parameters in delete confirmation requests.