CVE-2026-33586
Received Received - Intake

Email Spoofing via SMTP Envelope Manipulation in OVH Mail Servers

Vulnerability report for CVE-2026-33586, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: ENISA

Description

Authenticated users are able to manipulate both the SMTP envelope “Envelope-from” and “From” fields when sending emails through OVH mail servers. Due to OVH's default SPF configuration, which commonly includes include:mx.ovh.com, any authenticated user with a valid OVH email account can send messages that appear to originate from any OVH-hosted domains using the default SPF record. Since the SPF policy explicitly authorizes OVH mail servers (mx.ovh.com) to send mail on behalf of these domains, forged messages successfully pass SPF validation despite not being authorized by the impersonated domain owner.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
OVHcloud OVHcloud 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1188 The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.
CWE-346 The product does not properly verify that the source of data or communication is valid.
CWE-290 This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows authenticated users to modify the sender fields in emails sent through OVH mail servers. The SMTP envelope-from and From fields can be manipulated, making emails appear to come from any OVH-hosted domain. OVH's SPF configuration permits this by authorizing mx.ovh.com to send mail on behalf of these domains, allowing forged messages to bypass SPF validation.

Detection Guidance

This vulnerability involves forged emails passing SPF validation due to OVH's SPF configuration. Detection requires checking email headers for mismatches between the SMTP envelope-from and From fields, and verifying if emails originate from OVH mail servers while claiming to be from other domains. Inspect email logs for outbound messages with conflicting sender domains.

Impact Analysis

This vulnerability enables email spoofing, where attackers can send emails that appear legitimate and originate from trusted OVH domains. This could lead to phishing attacks, fraud, or reputational damage if recipients trust the forged emails. Users with OVH email accounts are at risk of having their accounts misused to send spoofed messages.

Compliance Impact

This vulnerability may violate compliance requirements that mandate email authenticity and integrity, such as GDPR's data protection principles or HIPAA's security rules for email communications. Spoofed emails could lead to unauthorized data disclosure or misrepresentation, potentially resulting in regulatory penalties or legal consequences.

Mitigation Strategies

Disable or restrict authenticated users' ability to modify SMTP envelope and From fields. Review and tighten SPF records to exclude OVH's default configuration. Monitor email logs for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-33586. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart