Executive brief
MailEnable Enterprise Premium, a popular Windows-based email server, contains a security flaw in its mobile administration portal. This vulnerability allows a standard email user to gain full administrative control over the entire mail server by reusing security tokens from their webmail session. An attacker could use this access to read any user's email, delete accounts, or change server-wide security settings, potentially leading to a total compromise of the organization's email infrastructure.
Technical details
An improper authorization vulnerability (CWE-639) exists in the WebAdmin mobile portal of MailEnable Enterprise Premium. The flaw allows an attacker to obtain an 'AuthenticationToken' cookie from the standard WebMail login endpoint by utilizing the 'PersistentLogin' parameter. This token, originally intended for low-privileged webmail access, can be replayed against the WebAdmin portal to bypass authentication checks. Successful exploitation grants the attacker highly privileged administrative access to the mail server. The vulnerability is fixed in version 10.56.
Affected products
- MailEnable MailEnable Enterprise Premium 10.55 and earlier
Timeline
- 2026-03-16: patched: Fixed in version 10.56
- 2026-05-08: disclosed: Initial disclosure and CVE assignment
- 2026-05-08: advisory: VulnCheck advisory published