PT-2026-39194 · Mailenable · Mailenable Enterprise Premium

·

CVE-2026-44400

·

Published

2026-05-08

·

Updated

2026-06-01

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MailEnable Enterprise Premium versions prior to 10.56
Description Improper authorization in the WebAdmin mobile portal allows attackers to bypass authentication checks by reusing AuthenticationToken cookies generated for low-privileged users. An attacker can obtain a token from the 'WebMail login' endpoint using the PersistentLogin parameter and replay it against the WebAdmin portal to perform highly privileged administrative actions.
Recommendations Update to a version later than 10.55.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44400

Affected Products

Mailenable Enterprise Premium