Description
N-able Mail Assure through April 2026 contains a design-level authorization flaw that allows an authenticated SMTP user to send outbound email using MAIL FROM addresses belonging to other tenants. When connecting to the SMTP TCP port and performing SMTP AUTH with valid credentials, the server accepts arbitrary sender domains without enforcing any domain-to-account binding. As a result, an attacker from any tenant can impersonate other tenant domains, producing messages that pass SPF and DMARC validation. NOTE: N-able's position is that the behavior is intended functionality of its shared SMTP relay architecture and that the service does not represent that it enforces per-tenant sender-domain binding.
Published: 2026-09-14
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Email impersonation via cross‑tenant sender spoofing
Action: Assess Impact
AI Analysis

Impact

This vulnerability arises from a design‑level authorization flaw in N‑able Mail Assure. When a user authenticates to the SMTP service, the server trusts all MAIL FROM addresses sent in the envelope without checking that the domain belongs to the tenant owning the credentials. As a result, an attacker from any tenant can send outbound mail that appears to come from other tenants. The flaw does not enable arbitrary code execution but allows email impersonation that can bypass SPF and DMARC checks, facilitating phishing, credential harvesting, or other deceptive campaigns.

Affected Systems

The affected product is N‑able Mail Assure.2026 release are vulnerable. The flaw exists in the shared SMTP relay architecture that does not enforce per‑tenant sender‑domain binding.

Risk and Exploitability

The vulnerability has a CVSS score of 4.3, indicating moderate severity. The EPSS score is < 1%, and it is not listed in the CISA KEV catalog. The flaw requires authentication via SMTP, which means that an attacker must have valid credentials on a tenant. Once authenticated, the attacker can send spoofed messages that will pass domain‑based authentication mechanisms. Because the design flaw is inherent to the architecture, the risk is confined to tenants that share the same SMTP relay instance. There is to log in can perform the abuse.

Generated by OpenCVE AI on September 15, 2026 at 16:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check the vendor’s website for a patch or newer release that implements per‑tenant sender‑domain binding.
  • Restrict the MAIL FROM envelope to only authorized sender domains for each tenant, using server‑side filtering or custom MTA rules.
  • Enable logging of MAIL FROM changes and monitor outbound traffic for suspicious sender domains to detect spoofing attempts.
  • Consider isolating tenants by deploying separate SMTP relay instances instead of a shared architecture.

Generated by OpenCVE AI on September 15, 2026 at 16:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared N-able
N-able mail Assure
Vendors & Products N-able
N-able mail Assure

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Title Cross‑Tenant Email Spoofing via Unrestricted MAIL FROM in N‑able Mail Assure

Mon, 14 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Title Design-level Authorization Flaw Enabling Cross‑Tenant Email Spoofing

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Title Design-level Authorization Flaw Enabling Cross‑Tenant Email Spoofing

Mon, 14 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
References

Mon, 14 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Description N-able Mail Assure through April 2026 contains a design-level authorization flaw that allows an authenticated SMTP user to send outbound email using MAIL FROM addresses belonging to other tenants. When connecting to the SMTP TCP port and performing SMTP AUTH with valid credentials, the server accepts arbitrary sender domains without enforcing any domain-to-account binding. As a result, an attacker from any tenant can impersonate other tenant domains, producing messages that pass SPF and DMARC validation. NOTE: N-able's position is that the behavior is intended functionality of its shared SMTP relay architecture and that the service does not represent that it enforces per-tenant sender-domain binding.
Weaknesses CWE-290
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

N-able Mail Assure
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-17T16:14:26.429Z

Reserved: 2025-12-19T00:00:00.000Z

Link: CVE-2025-68624

cve-icon Vulnrichment

Updated: 2026-09-14T00:23:07.359Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T01:16:27.220

Modified: 2026-09-22T20:00:03.713

Link: CVE-2025-68624

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:47:23Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing