PatchSiren cyber security CVE debrief
CVE-2026-33586 OVHcloud CVE debrief
Authenticated SMTP Sender Address Forgery allows attackers to send emails appearing to originate from any OVH-hosted domains due to OVH's default SPF configuration. This issue affects OVHcloud users with valid email accounts. The vulnerability enables malicious actors to manipulate both the SMTP envelope 'Envelope-from' and 'From' fields. As a result, any authenticated user with a valid OVH email account can send messages that appear to originate from any OVH-hosted domains using the default SPF record. Since the SPF policy explicitly authorizes OVH mail servers (mx.ovh.com) to send mail on behalf of these domains, forged messages successfully pass SPF validation despite not being
- Vendor
- OVHcloud
- Product
- Unknown
- CVSS
- MEDIUM 6.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
OVHcloud email users and administrators should assess exposure and review SPF configurations to prevent domain impersonation. They should also verify and update SPF configurations, monitor email logs for suspicious activity, and restrict email sending permissions for authenticated users. Additionally, they should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. It is essential to review the
Why it matters
Authenticated SMTP Sender Address Forgery in OVHcloud allows attackers to send emails appearing to originate from any OVH-hosted domains due to default SPF configuration. This issue affects OVHcloud users with valid email accounts, requiring review of SPF configurations and email sending permissions.
- Email domain impersonation possible for authenticated users
- SPF validation can be bypassed due to default configuration
- Email logs may require monitoring for suspicious activity
- Verification of affected versions and remediation steps is necessary
Technical summary
Authenticated users can manipulate SMTP envelope and 'From' fields, allowing them to send emails appearing to originate from any OVH-hosted domains due to OVH's default SPF configuration. The vulnerability is caused by the default SPF configuration, which authorizes OVH mail servers to send mail on behalf of OVH-hosted domains. This enables attackers to send forged emails that pass SPF validation. The issue affects OVHcloud users with valid email accounts, and it is essential to review SPF configurations and restrict email sending permissions to prevent
Defensive priority
Medium priority for OVHcloud email users and administrators to review SPF configurations and restrict email sending permissions.
Recommended defensive actions
- Review and restrict email sending permissions for authenticated users
- Verify and update SPF configurations to prevent domain impersonation
- Monitor email logs for suspicious activity
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and source item provide details on the vulnerability. However, specific versions affected and remediation steps require verification from OVHcloud. The issue is caused by OVH's default SPF configuration, which commonly includes include:mx.ovh.com. This allows any authenticated user with a valid OVH email account to send emails that appear to originate from any OVH-hosted domains. The default SPF record enables the forgery of sender addresses, potentially leading to phishing attacks or other malicious activities. To
Sources and references
Verified primary and authoritative sources
-
CVE-2026-33586 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-33586
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-33586 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-33586
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Authenticated SMTP Sender Address Forgery
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/33xxx/CVE-2026-33586.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://docs.ovhcloud.com/en/guides/web-cloud/email-and-collaborative-solutions/troubleshooting/email-rejected-cross-domain-spoofing
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.