PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-33586 OVHcloud CVE debrief

Authenticated SMTP Sender Address Forgery allows attackers to send emails appearing to originate from any OVH-hosted domains due to OVH's default SPF configuration. This issue affects OVHcloud users with valid email accounts. The vulnerability enables malicious actors to manipulate both the SMTP envelope 'Envelope-from' and 'From' fields. As a result, any authenticated user with a valid OVH email account can send messages that appear to originate from any OVH-hosted domains using the default SPF record. Since the SPF policy explicitly authorizes OVH mail servers (mx.ovh.com) to send mail on behalf of these domains, forged messages successfully pass SPF validation despite not being

Vendor
OVHcloud
Product
Unknown
CVSS
MEDIUM 6.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

OVHcloud email users and administrators should assess exposure and review SPF configurations to prevent domain impersonation. They should also verify and update SPF configurations, monitor email logs for suspicious activity, and restrict email sending permissions for authenticated users. Additionally, they should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. It is essential to review the

Why it matters

Authenticated SMTP Sender Address Forgery in OVHcloud allows attackers to send emails appearing to originate from any OVH-hosted domains due to default SPF configuration. This issue affects OVHcloud users with valid email accounts, requiring review of SPF configurations and email sending permissions.

  • Email domain impersonation possible for authenticated users
  • SPF validation can be bypassed due to default configuration
  • Email logs may require monitoring for suspicious activity
  • Verification of affected versions and remediation steps is necessary

Technical summary

Authenticated users can manipulate SMTP envelope and 'From' fields, allowing them to send emails appearing to originate from any OVH-hosted domains due to OVH's default SPF configuration. The vulnerability is caused by the default SPF configuration, which authorizes OVH mail servers to send mail on behalf of OVH-hosted domains. This enables attackers to send forged emails that pass SPF validation. The issue affects OVHcloud users with valid email accounts, and it is essential to review SPF configurations and restrict email sending permissions to prevent

Defensive priority

Medium priority for OVHcloud email users and administrators to review SPF configurations and restrict email sending permissions.

Recommended defensive actions

  • Review and restrict email sending permissions for authenticated users
  • Verify and update SPF configurations to prevent domain impersonation
  • Monitor email logs for suspicious activity
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and source item provide details on the vulnerability. However, specific versions affected and remediation steps require verification from OVHcloud. The issue is caused by OVH's default SPF configuration, which commonly includes include:mx.ovh.com. This allows any authenticated user with a valid OVH email account to send emails that appear to originate from any OVH-hosted domains. The default SPF record enables the forgery of sender addresses, potentially leading to phishing attacks or other malicious activities. To

Sources and references

Verified primary and authoritative sources

  • CVE-2026-33586 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-33586

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-33586 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-33586

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Authenticated SMTP Sender Address Forgery

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/33xxx/CVE-2026-33586.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://docs.ovhcloud.com/en/guides/web-cloud/email-and-collaborative-solutions/troubleshooting/email-rejected-cross-domain-spoofing

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.