{"id":"CVE-2026-33586","title":"Authenticated users are able to manipulate both the SMTP\nenvelope “Envelope-from” and “From” fields when sending\nemails through OVH mail servers.\n\n\n\nDue to OVH's default SPF configuration, which\ncommonly includes include:mx.ovh.com, any …","summary":"Authenticated users are able to manipulate both the SMTP\nenvelope “Envelope-from” and “From” fields when sending\nemails through OVH mail servers.\n\n\n\nDue to OVH's default SPF configuration, which\ncommonly includes include:mx.ovh.com, any …","severity":"medium","cvss":6.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N/E:A","cwe":["CWE-290","CWE-346","CWE-1188"],"vendor":"OVHcloud","product":"OVHcloud","affected":["OVHcloud < 2026-07-20"],"published":"2026-10-07","updated":"2026-10-07","sourceUpdated":"2026-10-07T16:17:47.643","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-33586","references":[{"url":"https://docs.ovhcloud.com/en/guides/web-cloud/email-and-collaborative-solutions/troubleshooting/email-rejected-cross-domain-spoofing","label":"a6d3dc9e-0591-4a13-bce7-0f5b31ff6158"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-10-07T15:36:04.135Z","slug":"CVE-2026-33586","body":"## Overview\n\nAuthenticated users are able to manipulate both the SMTP\nenvelope “Envelope-from” and “From” fields when sending\nemails through OVH mail servers.\n\n\n\nDue to OVH's default SPF configuration, which\ncommonly includes include:mx.ovh.com, any authenticated user with a\nvalid OVH email account can send messages that appear to originate from any\nOVH-hosted domains using the default SPF record. Since the SPF policy\nexplicitly authorizes OVH mail servers (mx.ovh.com) to send mail on behalf of\nthese domains, forged messages successfully pass SPF validation despite\nnot being authorized by the impersonated domain owner.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":35,"depthScoreParts":{"impact":34.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}