CVE-2026-44400 Details
Description
MailEnable Enterprise Premium 10.55 and earlier contains an improper authorization vulnerability in the WebAdmin mobile portal that allows attackers to bypass authentication checks by reusing AuthenticationToken cookies generated for low-privileged users. Attackers can obtain a token from the WebMail login endpoint using the PersistentLogin parameter and replay it against the WebAdmin portal to perform highly privileged administrative actions.
A vulnerability allowing authorization bypass has been identified in MailEnable Enterprise Premium versions through 10.55. This issue resides in the WebAdmin mobile portal, where attackers can exploit authentication checks by reusing AuthenticationToken cookies from low-privileged users. The tokens can be obtained from the WebMail login endpoint using the PersistentLogin parameter and then replayed in the WebAdmin portal to execute high-privilege administrative actions.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.mailenable.com/Premium-ReleaseNotes.txt | [email protected] | Release Notes |
| https://www.vulncheck.com/advisories/mailenable-enterprise-premium-authorization-bypass-via-webadmin | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| mailenable mailenable | < 10.56 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 1, 2026 | Initial Analysis | [email protected] |
| May 8, 2026 | New CVE Received | [email protected] |