MEDIUM
OVHcloud
CVE published 2026-10-07
CVE-2026-33586
Authenticated SMTP Sender Address Forgery allows attackers to send emails appearing to originate from any OVH-hosted domains due to OVH's default SPF configuration. This issue affects OVHcloud users with valid email accounts. The vulnerability enables malicious actors to manipulate both the SMTP envelope 'Envelope-from' and 'From' fields. As a result, any authenticated user with a valid OVH email account [truncated]