CVE-2026-101281
Received Received - Intake

Authentication Bypass in OpenDMARC SPF Macro Handler

Vulnerability report for CVE-2026-101281, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: VulDB

Description

A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_sp2_find_mailfrom_domain of the file libopendmarc/opendmarc_spf.c of the component SPF Macro Handler. This manipulation causes improper authentication. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch name: c48a74c758677fc5272a73eff15ffdbf8afda1a6. Applying a patch is the recommended action to fix this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
trusted_domain_project opendmarc to 1.4.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in OpenDMARC up to version 1.4.2, specifically in the SPF Macro Handler function opendmarc_sp2_find_mailfrom_domain. It allows improper authentication by manipulating the SPF check to always use 'postmaster' instead of the actual mailbox, bypassing per-local-part policies. This occurs when the victim domain's SPF record uses the %{l} macro. The flaw is due to incorrect handling of the local part in SPF validation.

Detection Guidance

To detect this vulnerability, check if your OpenDMARC version is 1.4.2 or earlier. Review SPF records for domains using the %{l} macro in the format v=spf1 exists:%{l}._spf.%{d} -all. Inspect logs for SPF failures or permerror responses during email authentication.

Impact Analysis

An attacker could forge emails to appear as if they come from a trusted local part, bypassing SPF checks and potentially delivering spoofed emails. This could lead to phishing attacks, unauthorized access, or reputation damage if the forged emails appear legitimate. The exploit is remotely accessible under specific SPF record conditions.

Compliance Impact

This vulnerability could undermine email authentication controls required by GDPR and HIPAA for secure communication. Spoofed emails may bypass security checks, risking unauthorized data access or breaches. Compliance with data protection regulations often depends on robust email validation, which this flaw weakens.

Mitigation Strategies

Apply the patch c48a74c758677fc5272a73eff15ffdbf8afda1a6 to OpenDMARC. Update to a version newer than 1.4.2. Review and adjust SPF records to avoid using the %{l} macro if possible. Monitor email authentication logs for SPF validation issues.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101281. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart