CVE-2026-41232 is an authentication bypass vulnerability in Froxlor server administration software prior to version 2.3.6. The flaw exists in the EmailSender::add() function, where incorrect array indexing during email address validation causes domain ownership checks to fail. This allows any authenticated customer to create sender aliases for email addresses on domains belonging to other customers, potentially enabling unauthorized email spoofing through Postfix's sender_login_maps integration. The vulnerability has a CVSS score of 5.0 (MEDIUM) with a network-accessible attack vector requiring low complexity and authenticated user privileges. While the confidentiality impact is none, the integrity impact is low with changed scope, allowing attackers to impersonate legitimate email addresses across domain boundaries. The EPSS score of 0.00025 indicates minimal real-world exploitation probability. There is no indication of active exploitation in the wild. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog, and community attention appears limited based on its inactive Hot List status. Organizations running Froxlor should prioritize updating to version 2.3.6 to remediate the domain ownership validation flaw, though the low EPSS score suggests this is not an immediately critical threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.3.6CPE matchmatch criteria | cpe:2.3:a:froxlor:froxlor:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.