Back

HIGH

Froxlor before 2.3.12 Authentication Bypass via EmailSender.add

Published Sep 26, 2026

Description

Froxlor through 2.3.10 does not enforce the mail.allow_external_domains policy in the EmailSender.add API command. When an administrator has enabled the allowed-sender feature but disabled external allowed-sender domains (mail.enable_allow_sender = 1, mail.allow_external_domains = 0), an authenticated customer with API access can still use EmailSender.add to register an arbitrary external sender address for their mailbox, which is stored despite the policy. This creates a bypass between the UI/administrator configuration and the API, and — where the generated mail configuration consumes the allowed-sender table — allows a customer to authorize sender identities outside their hosted domains, facilitating sender spoofing. Fixed in 2.3.12.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Sep 26, 2026
Updated Sep 26, 2026
Reserved Sep 26, 2026
CISA Vulnrichment
Updated Sep 26, 2026
NVD
Status Deferred
Modified Sep 26, 2026
Red Hat
Severity n/a
Public date n/a