PT-2026-39194 · Mailenable · Mailenable Enterprise Premium
Dninh
·
Published
2026-05-08
·
Updated
2026-05-09
·
CVE-2026-44400
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MailEnable Enterprise Premium versions prior to 10.56
Description
Improper authorization in the WebAdmin mobile portal allows attackers to bypass authentication checks by reusing
AuthenticationToken cookies generated for low-privileged users. An attacker can obtain a token from the 'WebMail login' endpoint using the PersistentLogin parameter and replay it against the WebAdmin portal to perform highly privileged administrative actions.Recommendations
Update to a version later than 10.55.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mailenable Enterprise Premium