Sceawere

Vulnerability Detail

CVE-2026-101280UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

OpenDMARC Multi-Record Authentication Bypass

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
6h ago
Vendor
Trusted Domain Project
Product
OpenDMARC
Attack Type
Authentication Bypass by Spoofing
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected is the function opendmarc_policy_query_dmarc of the component Multi-Record Set Handler. The manipulation results in authentication bypass by spoofing. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-09-29T01:16:44.193Z",
  "pubdate": "2026-09-29T01:16:44.193Z",
  "executiveSummary": "A critical vulnerability exists in the Trusted Domain Project OpenDMARC (up to version 1.4.2) within the opendmarc_policy_query_dmarc function.\nThe flaw originates in the Multi-Record Set Handler, allowing a remote, unauthenticated attacker to bypass DMARC authentication mechanisms.\nBy manipulating the handling of multiple DMARC records, an attacker can successfully spoof domains, rendering the email authentication framework ineffective.\nThis vulnerability presents a severe risk as it allows for the delivery of unauthorized or malicious emails that appear to originate from legitimate, authenticated domains.\nThe attack is remotely exploitable without requiring prior authentication or user interaction.\nThe lack of a vendor response to reported issues increases the risk posture for organizations relying on OpenDMARC for email security.\nExploitation tools are currently public, heightening the risk of active exploitation in the wild.",
  "technicalDetails": "The vulnerability resides within the opendmarc_policy_query_dmarc function of the Multi-Record Set Handler component in OpenDMARC versions 1.4.2 and earlier.\nThe root cause of this flaw is improper validation and logic handling when a domain publishes multiple DMARC records in DNS. The DMARC specification (RFC 7489) strictly prohibits the existence of multiple DMARC records for a single domain, stating that receivers must treat such configurations as invalid and ignore them.\nOpenDMARC, however, fails to correctly enforce this specification. When the Multi-Record Set Handler encounters a malformed DNS response containing multiple records, the opendmarc_policy_query_dmarc function fails to transition to an error or 'none' policy state. Instead, the logic incorrectly parses or defaults to a state that allows the policy to be bypassed or misinterpreted.\nThe exploitation flow begins when an attacker publishes multiple DMARC records for a domain under their control, or leverages a target domain that has inadvertently misconfigured its DNS by publishing duplicate DMARC TXT records. When the OpenDMARC parser processes the lookup result for this domain, the flawed function logic interprets the collision in a way that leads to a 'pass' result or an incorrect policy evaluation.\nBy forcing this logic error, the attacker successfully subverts the DMARC protocol check. This allows the attacker to transmit spoofed emails that are authenticated by OpenDMARC, despite failing the necessary SPF or DKIM alignment checks that DMARC is intended to enforce.\nBecause the vulnerability exists in the core policy evaluation routine, it is accessible to any remote sender targeting an organization utilizing the vulnerable version of OpenDMARC. No special privileges are required, and the attacker does not need to compromise the target server directly; they simply leverage the faulty DNS record processing logic.\nPost-exploitation impact includes the successful delivery of phishing, business email compromise (BEC), or malware campaigns that bypass standard email authentication headers. This undermines the trust model of the entire mail infrastructure, as the policy decision-making engine is essentially subverted. The exploit allows an attacker to spoof any domain that has multiple DMARC records present, facilitating high-confidence impersonation attacks."
}
CVE-2026-101280: OpenDMARC Multi-Record Authentication Bypass (HIGH Severity, CVSS: 7.3) | Sceawere