8.7
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
MailEnable Enterprise Premium 10.55 and earlier contains an improper authorization vulnerability in the WebAdmin mobile portal that allows attackers to bypass authentication checks by reusing AuthenticationToken cookies generated for low-privileged users. Attackers can obtain a token from the WebMail login endpoint using the PersistentLogin parameter and replay it against the WebAdmin portal to perform highly privileged administrative actions.
AI Analysis
Improper authorization vulnerability in WebAdmin mobile portal allowing attackers to bypass authentication checks and perform administrative actions
Basic Information
ID
CVE-2026-44400
Source
VulnCheck
Published
May 8, 2026 at 20:22
Affected Product
Vendor
MailEnable
Product
MailEnable Enterprise Premium
Affected Versions
MailEnable MailEnable Enterprise Premium 0
CWE Classification
AI Assessment
AI Score
8.7 / 10
AI Severity
High
Vendor
MailEnable
Product
MailEnable Enterprise Premium
Version
10.55 and earlier