Executive brief
Modoboa is an open-source mail hosting and management platform. A security flaw in the platform's account management interface allows a domain administrator to reset the password of any other user, including system-wide super-administrators. This could lead to a complete takeover of the entire mail server infrastructure by a malicious or compromised administrative account.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in the 'PUT /api/v1/accounts/{pk}/password/' endpoint of Modoboa. The application fails to properly validate that the authenticated domain administrator has the authority to modify the specific user account identified by the primary key ({pk}) in the request. By manipulating this identifier, an attacker with low-level domain administrative privileges can reset the password of any user, including super-administrators, bypassing object-level access controls. This vulnerability is addressed in version 2.9.0.
Affected products
- Modoboa Modoboa before 2.9.0
Timeline
- 2026-05-27: patched: Fix merged into master branch via pull request 4038
- 2026-06-29: disclosed: CVE published and NVD record created