← Back to CVE List
CVE-2026-33586NVD
Vulnerability Summary
Authenticated users are able to manipulate both the SMTP
envelope “Envelope-from” and “From” fields when sending
emails through OVH mail servers.
Due to OVH's default SPF configuration, which
commonly includes include:mx.ovh.com, any authenticated user with a
valid OVH email account can send messages that appear to originate from any
OVH-hosted domains using the default SPF record. Since the SPF policy
explicitly authorizes OVH mail servers (mx.ovh.com) to send mail on behalf of
these domains, forged messages successfully pass SPF validation despite
not being authorized by the impersonated domain owner.
envelope “Envelope-from” and “From” fields when sending
emails through OVH mail servers.
Due to OVH's default SPF configuration, which
commonly includes include:mx.ovh.com, any authenticated user with a
valid OVH email account can send messages that appear to originate from any
OVH-hosted domains using the default SPF record. Since the SPF policy
explicitly authorizes OVH mail servers (mx.ovh.com) to send mail on behalf of
these domains, forged messages successfully pass SPF validation despite
not being authorized by the impersonated domain owner.
CVSS v4.0 Base Metrics — Score 6.3 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredLow
User InteractionNone
Confidentiality (Vulnerable System)None
Integrity (Vulnerable System)None
Availability (Vulnerable System)None
Confidentiality (Subsequent System)None
Integrity (Subsequent System)High
Availability (Subsequent System)None
Affected & Patched Versions
- OVHcloud OVHcloud < 2026-07-20
- OVHcloud OVHcloud 2026-07-20