Incorrect authorization in Froxlor - CVE-2026-41232
Published: April 27, 2026
Froxlor
Detailed vulnerability description
The vulnerability allows a remote user to spoof email senders across customer domains.
The vulnerability exists due to incorrect authorization in EmailSender::add() when processing full email sender aliases. A remote user can add a sender alias for an email address on another customer's domain to spoof email senders across customer domains.
Only the full email address alias path is affected; the wildcard @domain path is not affected.