rootpwn

high · CVSS v3 7.3

CVE-2026-101280

OpenDMARC versions up to 1.4.2 contain a remote authentication bypass that allows attackers to spoof domain validation. The flaw resides in

Overview

OpenDMARC versions up to 1.4.2 contain a remote authentication bypass that allows attackers to spoof domain validation. The flaw resides in the opendmarc_policy_query_dmarc function of the Multi-Record Set Handler. This can compromise email authentication for affected mail servers.

Description

A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected is the function opendmarc_policy_query_dmarc of the component Multi-Record Set Handler. The manipulation results in authentication bypass by spoofing. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Impact

Confidentiality: attackers can forge domain validation, enabling spoofed emails. Integrity: malicious messages may bypass DMARC checks. Availability: not directly affected. Defenders: email administrators, mail server operators, security teams.

Remediation

Upgrade to OpenDMARC 1.4.3 or later where the vulnerability is fixed. If upgrade is not possible, disable the Multi-Record Set Handler or enforce strict DMARC checks manually. Monitor mail logs for suspicious DMARC bypass attempts and apply vendor patches as soon as available.

Risk context

Severity is high with CVSS 7.3. The vulnerability is publicly known and exploitable remotely, making it urgent for organizations running affected OpenDMARC versions to apply patches or mitigations promptly.

Affected products

  • Trusted Domain Project OpenDMARC 1.4.2
  • Trusted Domain Project OpenDMARC 1.4.1
  • Trusted Domain Project OpenDMARC 1.4.0
  • Trusted Domain Project OpenDMARC 1.3.9

Scores

Severity
high
CVSS v2
7.5
CVSS v3
7.3
CVSS v4
—
EPSS
—

email DMARC authentication bypass remote high severity OpenDMARC spoofing

← All CVEs