Sceawere

Vulnerability Detail

CVE-2026-101281UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

OpenDMARC SPF Macro Authentication Bypass

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
6h ago
Vendor
Trusted Domain Project
Product
OpenDMARC
Attack Type
Improper Authentication
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_sp2_find_mailfrom_domain of the file libopendmarc/opendmarc_spf.c of the component SPF Macro Handler. This manipulation causes improper authentication. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch name: c48a74c758677fc5272a73eff15ffdbf8afda1a6. Applying a patch is the recommended action to fix this issue.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-09-29T01:16:44.367Z",
  "pubdate": "2026-09-29T01:16:44.367Z",
  "executiveSummary": "A critical vulnerability exists in the SPF Macro Handler component of Trusted Domain Project OpenDMARC, affecting versions up to 1.4.2.\nThe flaw stems from improper authentication logic within the opendmarc_sp2_find_mailfrom_domain function, leading to a failure in correctly validating SPF macro-based domains.\nThis vulnerability allows remote, unauthenticated attackers to bypass SPF-based authentication checks, potentially facilitating email spoofing and the delivery of fraudulent communications.\nThe risk is elevated due to the existence of publicly available exploit code, which may be leveraged by threat actors to manipulate mail flow.\nImmediate patching is required to restore the integrity of DMARC and SPF verification processes.",
  "technicalDetails": "The vulnerability is located in the SPF Macro Handler component, specifically within the opendmarc_sp2_find_mailfrom_domain function defined in libopendmarc/opendmarc_spf.c.\nThe root cause of this defect lies in the incorrect processing and extraction of domain identifiers when SPF macros are utilized. During the evaluation of the 'MAIL FROM' domain, the function fails to perform adequate sanitization or logical validation of the provided macro expansion, leading to an inconsistent state in the authentication mechanism.\nThe attack flow involves a remote attacker crafting a malicious email message that utilizes specific SPF macro configurations. When OpenDMARC attempts to resolve the domain for verification purposes via the vulnerable function, the flawed logic incorrectly identifies or authorizes the domain, effectively bypassing the intended security policy.\nBecause OpenDMARC functions as an integral part of the email filtering pipeline, this bypass causes the DMARC check to operate on incorrect assumptions regarding the legitimacy of the sender's domain. This manipulation is possible without prior authentication, as the processing occurs during the standard email delivery sequence where the attacker is merely interacting with the receiving mail server.\nExploitation allows an attacker to masquerade as a legitimate sender by subverting the SPF-dependent component of the DMARC authentication chain. This results in the potential delivery of spoofed emails that are improperly marked as authenticated, thereby bypassing reputation-based filters and anti-spam controls. The integrity of the SPF/DMARC implementation is invalidated, as the macro handler fails to restrict domain lookup to authorized scopes, creating a logic error that the security policy is unable to mitigate internally.\nThe vulnerability is present in all OpenDMARC versions up to 1.4.2. Successful exploitation necessitates only network reachability to the mail transfer agent (MTA) utilizing the vulnerable OpenDMARC library."
}
CVE-2026-101281: OpenDMARC SPF Macro Authentication Bypass (HIGH Severity, CVSS: 7.3) | Sceawere