CVE-2025-68624: CWE-290 Authentication Bypass by Spoofing in N-able Mail Assure
N-able Mail Assure through April 2026 has a design-level authorization flaw that allows authenticated SMTP users to send outbound emails using MAIL FROM addresses of other tenants. The SMTP server does not enforce domain-to-account binding after SMTP AUTH, enabling sender domain spoofing across tenants. N-able states this behavior is intended as part of its shared SMTP relay design and does not enforce per-tenant sender-domain binding. This vulnerability has a medium severity with a CVSS score of 4.3.
AI Analysis
Technical Summary
CVE-2025-68624 describes an authentication bypass by spoofing vulnerability (CWE-290) in N-able Mail Assure's SMTP service. Authenticated SMTP users can specify arbitrary MAIL FROM addresses belonging to other tenants because the server does not enforce domain-to-account binding post-authentication. This allows attackers to impersonate other tenant domains, producing emails that pass SPF and DMARC validation. N-able considers this behavior intentional within its shared SMTP relay architecture and does not provide per-tenant sender-domain enforcement.
Potential Impact
An attacker with valid SMTP credentials from any tenant can send emails that appear to originate from other tenants' domains. This can lead to domain impersonation and potentially undermine trust in email authenticity, as spoofed messages can pass SPF and DMARC checks. However, there is no direct confidentiality or availability impact reported.
Mitigation Recommendations
No official patch or fix is available. N-able states this behavior is intended functionality of its shared SMTP relay architecture and does not enforce per-tenant sender-domain binding. Users should be aware of this design choice and consider compensating controls outside the service if domain spoofing risk is unacceptable. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
CVE-2025-68624: CWE-290 Authentication Bypass by Spoofing in N-able Mail Assure
Description
N-able Mail Assure through April 2026 has a design-level authorization flaw that allows authenticated SMTP users to send outbound emails using MAIL FROM addresses of other tenants. The SMTP server does not enforce domain-to-account binding after SMTP AUTH, enabling sender domain spoofing across tenants. N-able states this behavior is intended as part of its shared SMTP relay design and does not enforce per-tenant sender-domain binding. This vulnerability has a medium severity with a CVSS score of 4.3.
CVSS v3.1
Score 4.3medium
Affected software
N-able
Mail Assure
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-68624 describes an authentication bypass by spoofing vulnerability (CWE-290) in N-able Mail Assure's SMTP service. Authenticated SMTP users can specify arbitrary MAIL FROM addresses belonging to other tenants because the server does not enforce domain-to-account binding post-authentication. This allows attackers to impersonate other tenant domains, producing emails that pass SPF and DMARC validation. N-able considers this behavior intentional within its shared SMTP relay architecture and does not provide per-tenant sender-domain enforcement.
Potential Impact
An attacker with valid SMTP credentials from any tenant can send emails that appear to originate from other tenants' domains. This can lead to domain impersonation and potentially undermine trust in email authenticity, as spoofed messages can pass SPF and DMARC checks. However, there is no direct confidentiality or availability impact reported.
Mitigation Recommendations
No official patch or fix is available. N-able states this behavior is intended functionality of its shared SMTP relay architecture and does not enforce per-tenant sender-domain binding. Users should be aware of this design choice and consider compensating controls outside the service if domain spoofing risk is unacceptable. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2025-12-19T00:00:00.000Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aa7478a55bf5e2cf54ed5cf
Added to database: 09/14/2026, 01:02:02 UTC
Last enriched: 09/14/2026, 01:16:51 UTC
Last updated: 09/14/2026, 02:03:16 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.