CVE-2026-33586 PUBLISHED

Authenticated SMTP Sender Address Forgery

Assigner: ENISA
Reserved: 23.03.2026 Published: 07.10.2026 Updated: 07.10.2026

Authenticated users are able to manipulate both the SMTP envelope “Envelope-from” and “From” fields when sending emails through OVH mail servers.

Due to OVH's default SPF configuration, which commonly includes include:mx.ovh.com, any authenticated user with a valid OVH email account can send messages that appear to originate from any OVH-hosted domains using the default SPF record. Since the SPF policy explicitly authorizes OVH mail servers (mx.ovh.com) to send mail on behalf of these domains, forged messages successfully pass SPF validation despite not being authorized by the impersonated domain owner.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N/E:A
CVSS Score: 6.3

Product Status

Vendor OVHcloud
Product OVHcloud
Versions Default: unaffected
  • affected from 0 to 2026-07-20 (excl.)

Credits

  • Abdullah HAMED of ENGIE IT Offensive Cybersecurity Team finder

References

Problem Types

  • CWE-1188 Initialization of a resource with an insecure default CWE
  • CWE-346: Origin Validation Error CWE
  • CWE-290 Authentication bypass by spoofing CWE