Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 29 Sep 2026 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_sp2_find_mailfrom_domain of the file libopendmarc/opendmarc_spf.c of the component SPF Macro Handler. This manipulation causes improper authentication. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch name: c48a74c758677fc5272a73eff15ffdbf8afda1a6. Applying a patch is the recommended action to fix this issue. | |
| Title | Trusted Domain Project OpenDMARC SPF Macro opendmarc_spf.c opendmarc_sp2_find_mailfrom_domain improper authentication | |
| First Time appeared |
Trusted Domain Project
Trusted Domain Project opendmarc |
|
| Weaknesses | CWE-287 | |
| CPEs | cpe:2.3:a:trusted_domain_project:opendmarc:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Trusted Domain Project
Trusted Domain Project opendmarc |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-29T00:45:11.946Z
Reserved: 2026-09-28T11:52:51.804Z
Link: CVE-2026-101281
No data.
Status : Received
Published: 2026-09-29T01:16:44.367
Modified: 2026-09-29T01:16:44.367
Link: CVE-2026-101281
No data.
OpenCVE Enrichment
Updated: 2026-09-29T03:15:04Z
-
CWE-287
Improper Authentication