Description
A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected is the function opendmarc_policy_query_dmarc of the component Multi-Record Set Handler. The manipulation results in authentication bypass by spoofing. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-29
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Authentication bypass leading to email spoofing
Action: Immediate Patch
AI Analysis

Impact

A function in Trusted Domain Project OpenDMARC, namely opendmarc_policy_query_dmarc within the Multi‑Record Set Handler, is vulnerable to manipulation that allows an attacker to bypass authentication checks. By forging requests to this function, an adversary can spoof DMARC authentication, making legitimate email traffic appear authentic. This permits the delivery of forged or malicious messages to legitimate recipients without triggering standard DMARC defenses.

Affected Systems

The vulnerability impacts all installations of Trusted Domain Project OpenDMARC version 1.4.2 and earlier. The affected component is the Multi‑Record Set Handler in the OpenDMARC package, which is deployed in mail servers and email gateway solutions that rely on DMARC validation.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity impact. The exploit is remote and can be performed by an unauthenticated attacker with network access to the OpenDMARC service. The EPSS score is not available, and the vulnerability is not yet listed in the CISA KEV catalog. Attackers can leverage publicly available exploit code or craft custom requests to trigger the authentication bypass.

Generated by OpenCVE AI on September 29, 2026 at 02:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade OpenDMARC to a version that contains the patch for the opendmarc_policy_query_dmarc function; if a patch is not yet released, regularly check the vendor’s website for updates.
  • Limit network exposure of the Multi‑Record Set Handler by restricting access to trusted IP ranges or internal networks; apply firewall rules to block external access if the service is not intended to be publicly reachable.
  • Enhance monitoring of DMARC logs to detect anomalous authentication bypass attempts and implement alerts for suspicious patterns indicative of spoofing.
  • If no patch is available in a timely manner, consider disabling the vulnerable Multi‑Record Set Handler endpoint via configuration or applying application‑level filters to block the specific request types used in the exploit.

Generated by OpenCVE AI on September 29, 2026 at 02:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected is the function opendmarc_policy_query_dmarc of the component Multi-Record Set Handler. The manipulation results in authentication bypass by spoofing. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Trusted Domain Project OpenDMARC Multi-Record Set opendmarc_policy_query_dmarc authentication spoofing
First Time appeared Trusted Domain Project
Trusted Domain Project opendmarc
Weaknesses CWE-287
CWE-290
CPEs cpe:2.3:a:trusted_domain_project:opendmarc:*:*:*:*:*:*:*:*
Vendors & Products Trusted Domain Project
Trusted Domain Project opendmarc
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Trusted Domain Project Opendmarc
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-29T00:30:15.504Z

Reserved: 2026-09-28T11:52:48.230Z

Link: CVE-2026-101280

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T01:16:44.193

Modified: 2026-09-29T01:16:44.193

Link: CVE-2026-101280

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T02:30:10Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-290

    Authentication Bypass by Spoofing