Design-Level Authorization Flaw in N-able Mail Assure Affects Multiple Tenants
CVE-2025-68624

4.3MEDIUM

Key Information:

Vendor

N-able

Vendor
CVE Published:
14 September 2026

What is CVE-2025-68624?

The N-able Mail Assure service contains a design-level vulnerability that enables unauthorized dispatch of emails by authenticated SMTP users. This flaw permits users to utilize MAIL FROM addresses belonging to other tenants, effectively allowing one tenant to impersonate the domains of others. During SMTP authentication, the system fails to enforce strict sender-domain binding according to tenant accounts, leading to potential misuse where attacker-generated messages can pass SPF and DMARC validations. N-able asserts that this design is intentional to facilitate its shared SMTP relay architecture.

Affected Version(s)

Mail Assure 0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.