Sploitus

CVE-2026-41232

No indexed exploits for CVE-2026-41232 yet

Froxlor is open source server administration software. Prior to version 2.3.6, in `EmailSender::add()`, the domain ownership validation for full email sender aliases uses the wrong array index when splitting the email address, passing the local part instead of the domain to `validateLocalDomainOwnership()`. This causes the ownership check to always pass for non-existent "domains," allowing any authenticated customer to add sender aliases for email addresses on domains belonging to other customers. Postfix's `sender_login_maps` then authorizes the attacker to send emails as those addresses. Version 2.3.6 fixes the issue.

Affected products
Froxlor
Froxlor
< 2.3.6
Fix
Available
CVSS 3.1
5.0 MEDIUM
EPSS
0.2% (14th percentile)
Weakness
CWE-863
NVD status
Analyzed
Published
2026-04-23
CVE-2026-41232 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-41232 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-41232 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.