---
id: CVE-2026-33586
title: |-
  Authenticated users are able to manipulate both the SMTP
  envelope “Envelope-from” and “From” fields when sending
  emails through OVH mail servers.



  Due to OVH's default SPF configuration, which
  commonly includes include:mx.ovh.com, any …
summary: |-
  Authenticated users are able to manipulate both the SMTP
  envelope “Envelope-from” and “From” fields when sending
  emails through OVH mail servers.



  Due to OVH's default SPF configuration, which
  commonly includes include:mx.ovh.com, any …
severity: medium
cvss: 6.3
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N/E:A'
cwe:
  - CWE-290
  - CWE-346
  - CWE-1188
vendor: OVHcloud
product: OVHcloud
affected:
  - OVHcloud < 2026-07-20
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T16:17:47.643'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-33586'
references:
  - url: >-
      https://docs.ovhcloud.com/en/guides/web-cloud/email-and-collaborative-solutions/troubleshooting/email-rejected-cross-domain-spoofing
    label: a6d3dc9e-0591-4a13-bce7-0f5b31ff6158
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-07T15:36:04.135Z'
---

## Overview

Authenticated users are able to manipulate both the SMTP
envelope “Envelope-from” and “From” fields when sending
emails through OVH mail servers.



Due to OVH's default SPF configuration, which
commonly includes include:mx.ovh.com, any authenticated user with a
valid OVH email account can send messages that appear to originate from any
OVH-hosted domains using the default SPF record. Since the SPF policy
explicitly authorizes OVH mail servers (mx.ovh.com) to send mail on behalf of
these domains, forged messages successfully pass SPF validation despite
not being authorized by the impersonated domain owner.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
