Email Spoofing Vulnerability in Froxlor by Froxlor
CVE-2026-100718
7.1HIGH
What is CVE-2026-100718?
The Froxlor software version 2.3.10 and earlier contains a vulnerability that allows authenticated users with API access to exploit the EmailSender.add API command by bypassing the mail.allow_external_domains policy. If the administrator has enabled sender restrictions but disabled external domains, these settings can be sidestepped, allowing customers to register external sender addresses. This flaw enables users to authorize sending identities from domains not managed by the system, opening the door to potential spoofing attacks, where emails can appear to originate from legitimate domains without authorization. The issue is addressed in version 2.3.12.
Affected Version(s)
froxlor 0 < 2.3.12
froxlor 2.3.12
