CVE-2026-44400
EUVD-2026-2882708.05.2026, 21:16
MailEnable Enterprise Premium 10.55 and earlier contains an improper authorization vulnerability in the WebAdmin mobile portal that allows attackers to bypass authentication checks by reusing AuthenticationToken cookies generated for low-privileged users. Attackers can obtain a token from the WebMail login endpoint using the PersistentLogin parameter and replay it against the WebAdmin portal to perform highly privileged administrative actions.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| mailenable | mailenable | 𝑥 < 10.56 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration