PT-2026-39194 · Mailenable · Mailenable Enterprise Premium

Dninh

·

Published

2026-05-08

·

Updated

2026-05-09

·

CVE-2026-44400

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MailEnable Enterprise Premium versions prior to 10.56
Description Improper authorization in the WebAdmin mobile portal allows attackers to bypass authentication checks by reusing AuthenticationToken cookies generated for low-privileged users. An attacker can obtain a token from the 'WebMail login' endpoint using the PersistentLogin parameter and replay it against the WebAdmin portal to perform highly privileged administrative actions.
Recommendations Update to a version later than 10.55.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-44400

Affected Products

Mailenable Enterprise Premium