Email Spoofing Vulnerability in Froxlor by Froxlor
CVE-2026-100718

7.1HIGH

Key Information:

Vendor

Froxlor

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100718?

The Froxlor software version 2.3.10 and earlier contains a vulnerability that allows authenticated users with API access to exploit the EmailSender.add API command by bypassing the mail.allow_external_domains policy. If the administrator has enabled sender restrictions but disabled external domains, these settings can be sidestepped, allowing customers to register external sender addresses. This flaw enables users to authorize sending identities from domains not managed by the system, opening the door to potential spoofing attacks, where emails can appear to originate from legitimate domains without authorization. The issue is addressed in version 2.3.12.

Affected Version(s)

froxlor 0 < 2.3.12

froxlor 2.3.12

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

muhammadahmad62
.