Improper Authentication Vulnerability in Trusted Domain Project OpenDMARC
CVE-2026-101016
Key Information:
- Vendor
Trusted Domain Project
- Status
- Vendor
- CVE Published:
- 28 September 2026
Badges
What is CVE-2026-101016?
A security flaw has been identified in OpenDMARC, specifically in the opendmarc_policy_parse_dmarc function within the library libopendmarc/opendmarc_policy.c. This issue stems from the manipulation of parameters such as fo, rf, ri, pct, sp, adkim, aspf, rua, and ruf, leading to improper handling of exceptional conditions. The discovered vulnerability opens the door for potential remote exploitation, posing a significant risk if left unaddressed. Notably, this issue was disclosed publicly, and attempts to inform the vendor regarding the vulnerability went unanswered.
Affected Version(s)
OpenDMARC 1.4.0
OpenDMARC 1.4.1
OpenDMARC 1.4.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
