PatchSiren

OVHcloud CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM OVHcloud CVE published 2026-10-07

CVE-2026-33586

Authenticated SMTP Sender Address Forgery allows attackers to send emails appearing to originate from any OVH-hosted domains due to OVH's default SPF configuration. This issue affects OVHcloud users with valid email accounts. The vulnerability enables malicious actors to manipulate both the SMTP envelope 'Envelope-from' and 'From' fields. As a result, any authenticated user with a valid OVH email account [truncated]