Impact
This vulnerability arises from a design‑level authorization flaw in N‑able Mail Assure. When a user authenticates to the SMTP service, the server trusts all MAIL FROM addresses sent in the envelope without checking that the domain belongs to the tenant owning the credentials. As a result, an attacker from any tenant can send outbound mail that appears to come from other tenants. The flaw does not enable arbitrary code execution but allows email impersonation that can bypass SPF and DMARC checks, facilitating phishing, credential harvesting, or other deceptive campaigns.
Affected Systems
The affected product is N‑able Mail Assure.2026 release are vulnerable. The flaw exists in the shared SMTP relay architecture that does not enforce per‑tenant sender‑domain binding.
Risk and Exploitability
The vulnerability has a CVSS score of 4.3, indicating moderate severity. The EPSS score is < 1%, and it is not listed in the CISA KEV catalog. The flaw requires authentication via SMTP, which means that an attacker must have valid credentials on a tenant. Once authenticated, the attacker can send spoofed messages that will pass domain‑based authentication mechanisms. Because the design flaw is inherent to the architecture, the risk is confined to tenants that share the same SMTP relay instance. There is to log in can perform the abuse.
OpenCVE Enrichment