CVE-2026-101280
Received Received - Intake

Authentication Bypass in OpenDMARC via Spoofing

Vulnerability report for CVE-2026-101280, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: VulDB

Description

A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected is the function opendmarc_policy_query_dmarc of the component Multi-Record Set Handler. The manipulation results in authentication bypass by spoofing. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
trusted_domain_project opendmarc to 1.4.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CWE-290 This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects OpenDMARC, a software that validates email senders using DMARC records. It incorrectly handles multiple DMARC TXT records by applying the first valid record instead of discarding all when more than one exists. This allows attackers to downgrade a domain's DMARC policy from reject or quarantine to none, bypassing email authentication.

Detection Guidance

Check OpenDMARC version with 'opendmarc --version' to confirm if it is 1.4.2 or earlier. Inspect DNS TXT records for _dmarc.yourdomain.com to see if multiple DMARC records exist. Use 'dig TXT _dmarc.yourdomain.com' to verify record order and presence of competing policies like p=none.

Impact Analysis

If exploited, this vulnerability could allow attackers to send spoofed emails that appear legitimate, potentially leading to phishing attacks, unauthorized access, or data breaches. Email security relying on DMARC enforcement would be weakened.

Compliance Impact

This vulnerability could undermine compliance with email security requirements in GDPR and HIPAA, which mandate strong authentication and protection against spoofing. Failure to enforce DMARC policies may result in non-compliance and increased risk of data breaches.

Mitigation Strategies

Upgrade OpenDMARC to the latest patched version if available. Ensure DNS DMARC TXT records contain only one valid policy record. Monitor DNS responses for unexpected record order or competing policies. If upgrading is not possible, consider switching to an alternative DMARC implementation that complies with RFC 7489 and RFC 9989.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101280. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart