Vulnerability Details CVE-2026-44400
MailEnable Enterprise Premium 10.55 and earlier contains an improper authorization vulnerability in the WebAdmin mobile portal that allows attackers to bypass authentication checks by reusing AuthenticationToken cookies generated for low-privileged users. Attackers can obtain a token from the WebMail login endpoint using the PersistentLogin parameter and replay it against the WebAdmin portal to perform highly privileged administrative actions.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 9.0%
CVSS Severity
CVSS v3 Score 8.1
Products affected by CVE-2026-44400
-
cpe:2.3:a:mailenable:mailenable:10.00
-
cpe:2.3:a:mailenable:mailenable:10.10
-
cpe:2.3:a:mailenable:mailenable:10.11
-
cpe:2.3:a:mailenable:mailenable:10.12
-
cpe:2.3:a:mailenable:mailenable:10.13
-
cpe:2.3:a:mailenable:mailenable:10.14
-
cpe:2.3:a:mailenable:mailenable:10.15
-
cpe:2.3:a:mailenable:mailenable:10.16
-
cpe:2.3:a:mailenable:mailenable:10.17
-
cpe:2.3:a:mailenable:mailenable:10.18
-
cpe:2.3:a:mailenable:mailenable:10.19
-
cpe:2.3:a:mailenable:mailenable:10.20
-
cpe:2.3:a:mailenable:mailenable:10.21
-
cpe:2.3:a:mailenable:mailenable:10.22
-
cpe:2.3:a:mailenable:mailenable:10.23
-
cpe:2.3:a:mailenable:mailenable:10.24
-
cpe:2.3:a:mailenable:mailenable:10.25
-
cpe:2.3:a:mailenable:mailenable:10.26
-
cpe:2.3:a:mailenable:mailenable:10.27
-
cpe:2.3:a:mailenable:mailenable:10.28
-
cpe:2.3:a:mailenable:mailenable:10.29
-
cpe:2.3:a:mailenable:mailenable:10.30
-
cpe:2.3:a:mailenable:mailenable:10.31
-
cpe:2.3:a:mailenable:mailenable:10.32
-
cpe:2.3:a:mailenable:mailenable:10.33
-
cpe:2.3:a:mailenable:mailenable:10.34
-
cpe:2.3:a:mailenable:mailenable:10.35
-
cpe:2.3:a:mailenable:mailenable:10.36
-
cpe:2.3:a:mailenable:mailenable:10.37
-
cpe:2.3:a:mailenable:mailenable:10.38
-
cpe:2.3:a:mailenable:mailenable:10.39
-
cpe:2.3:a:mailenable:mailenable:10.40
-
cpe:2.3:a:mailenable:mailenable:10.41
-
cpe:2.3:a:mailenable:mailenable:10.42
-
cpe:2.3:a:mailenable:mailenable:10.43
-
cpe:2.3:a:mailenable:mailenable:6.0
-
cpe:2.3:a:mailenable:mailenable:6.01
-
cpe:2.3:a:mailenable:mailenable:6.02
-
cpe:2.3:a:mailenable:mailenable:6.03
-
cpe:2.3:a:mailenable:mailenable:6.5
-
cpe:2.3:a:mailenable:mailenable:6.51
-
cpe:2.3:a:mailenable:mailenable:6.52
-
cpe:2.3:a:mailenable:mailenable:6.53
-
cpe:2.3:a:mailenable:mailenable:6.54
-
cpe:2.3:a:mailenable:mailenable:6.55
-
cpe:2.3:a:mailenable:mailenable:6.56
-
cpe:2.3:a:mailenable:mailenable:6.57
-
cpe:2.3:a:mailenable:mailenable:6.58
-
cpe:2.3:a:mailenable:mailenable:6.59
-
cpe:2.3:a:mailenable:mailenable:6.60
-
cpe:2.3:a:mailenable:mailenable:6.61
-
cpe:2.3:a:mailenable:mailenable:6.62
-
cpe:2.3:a:mailenable:mailenable:6.63
-
cpe:2.3:a:mailenable:mailenable:6.64
-
cpe:2.3:a:mailenable:mailenable:6.65
-
cpe:2.3:a:mailenable:mailenable:6.70
-
cpe:2.3:a:mailenable:mailenable:6.71
-
cpe:2.3:a:mailenable:mailenable:6.72
-
cpe:2.3:a:mailenable:mailenable:6.73
-
cpe:2.3:a:mailenable:mailenable:6.74
-
cpe:2.3:a:mailenable:mailenable:6.75
-
cpe:2.3:a:mailenable:mailenable:6.76
-
cpe:2.3:a:mailenable:mailenable:6.77
-
cpe:2.3:a:mailenable:mailenable:6.78
-
cpe:2.3:a:mailenable:mailenable:6.79
-
cpe:2.3:a:mailenable:mailenable:6.80
-
cpe:2.3:a:mailenable:mailenable:6.81
-
cpe:2.3:a:mailenable:mailenable:6.82
-
cpe:2.3:a:mailenable:mailenable:6.83
-
cpe:2.3:a:mailenable:mailenable:6.84
-
cpe:2.3:a:mailenable:mailenable:6.85
-
cpe:2.3:a:mailenable:mailenable:6.86
-
cpe:2.3:a:mailenable:mailenable:6.87
-
cpe:2.3:a:mailenable:mailenable:6.88
-
cpe:2.3:a:mailenable:mailenable:6.89
-
cpe:2.3:a:mailenable:mailenable:6.90
-
cpe:2.3:a:mailenable:mailenable:7.0
-
cpe:2.3:a:mailenable:mailenable:7.01
-
cpe:2.3:a:mailenable:mailenable:7.02
-
cpe:2.3:a:mailenable:mailenable:7.03
-
cpe:2.3:a:mailenable:mailenable:7.04
-
cpe:2.3:a:mailenable:mailenable:7.05
-
cpe:2.3:a:mailenable:mailenable:7.06
-
cpe:2.3:a:mailenable:mailenable:7.07
-
cpe:2.3:a:mailenable:mailenable:7.08
-
cpe:2.3:a:mailenable:mailenable:7.09
-
cpe:2.3:a:mailenable:mailenable:7.50
-
cpe:2.3:a:mailenable:mailenable:7.51
-
cpe:2.3:a:mailenable:mailenable:7.52
-
cpe:2.3:a:mailenable:mailenable:7.53
-
cpe:2.3:a:mailenable:mailenable:7.54
-
cpe:2.3:a:mailenable:mailenable:7.55
-
cpe:2.3:a:mailenable:mailenable:7.56
-
cpe:2.3:a:mailenable:mailenable:7.57
-
cpe:2.3:a:mailenable:mailenable:7.58
-
cpe:2.3:a:mailenable:mailenable:7.59
-
cpe:2.3:a:mailenable:mailenable:7.60
-
cpe:2.3:a:mailenable:mailenable:7.61
-
cpe:2.3:a:mailenable:mailenable:7.62
-
cpe:2.3:a:mailenable:mailenable:8.00
-
cpe:2.3:a:mailenable:mailenable:8.01
-
cpe:2.3:a:mailenable:mailenable:8.02
-
cpe:2.3:a:mailenable:mailenable:8.03
-
cpe:2.3:a:mailenable:mailenable:8.04
-
cpe:2.3:a:mailenable:mailenable:8.50
-
cpe:2.3:a:mailenable:mailenable:8.51
-
cpe:2.3:a:mailenable:mailenable:8.52
-
cpe:2.3:a:mailenable:mailenable:8.53
-
cpe:2.3:a:mailenable:mailenable:8.54
-
cpe:2.3:a:mailenable:mailenable:8.55
-
cpe:2.3:a:mailenable:mailenable:8.56
-
cpe:2.3:a:mailenable:mailenable:8.57
-
cpe:2.3:a:mailenable:mailenable:8.58
-
cpe:2.3:a:mailenable:mailenable:8.59
-
cpe:2.3:a:mailenable:mailenable:8.60
-
cpe:2.3:a:mailenable:mailenable:8.61
-
cpe:2.3:a:mailenable:mailenable:8.62
-
cpe:2.3:a:mailenable:mailenable:8.63
-
cpe:2.3:a:mailenable:mailenable:8.64
-
cpe:2.3:a:mailenable:mailenable:8.65
-
cpe:2.3:a:mailenable:mailenable:8.66
-
cpe:2.3:a:mailenable:mailenable:8.67
-
cpe:2.3:a:mailenable:mailenable:9.0
-
cpe:2.3:a:mailenable:mailenable:9.01
-
cpe:2.3:a:mailenable:mailenable:9.02
-
cpe:2.3:a:mailenable:mailenable:9.03
-
cpe:2.3:a:mailenable:mailenable:9.04
-
cpe:2.3:a:mailenable:mailenable:9.05
-
cpe:2.3:a:mailenable:mailenable:9.10
-
cpe:2.3:a:mailenable:mailenable:9.11
-
cpe:2.3:a:mailenable:mailenable:9.12
-
cpe:2.3:a:mailenable:mailenable:9.13
-
cpe:2.3:a:mailenable:mailenable:9.14
-
cpe:2.3:a:mailenable:mailenable:9.15
-
cpe:2.3:a:mailenable:mailenable:9.16
-
cpe:2.3:a:mailenable:mailenable:9.17
-
cpe:2.3:a:mailenable:mailenable:9.18
-
cpe:2.3:a:mailenable:mailenable:9.50
-
cpe:2.3:a:mailenable:mailenable:9.51
-
cpe:2.3:a:mailenable:mailenable:9.52
-
cpe:2.3:a:mailenable:mailenable:9.53
-
cpe:2.3:a:mailenable:mailenable:9.54
-
cpe:2.3:a:mailenable:mailenable:9.60
-
cpe:2.3:a:mailenable:mailenable:9.61
-
cpe:2.3:a:mailenable:mailenable:9.62
-
cpe:2.3:a:mailenable:mailenable:9.70
-
cpe:2.3:a:mailenable:mailenable:9.71
-
cpe:2.3:a:mailenable:mailenable:9.72
-
cpe:2.3:a:mailenable:mailenable:9.73
-
cpe:2.3:a:mailenable:mailenable:9.74
-
cpe:2.3:a:mailenable:mailenable:9.75
-
cpe:2.3:a:mailenable:mailenable:9.76
-
cpe:2.3:a:mailenable:mailenable:9.77
-
cpe:2.3:a:mailenable:mailenable:9.78
-
cpe:2.3:a:mailenable:mailenable:9.79
-
cpe:2.3:a:mailenable:mailenable:9.80
-
cpe:2.3:a:mailenable:mailenable:9.81
-
cpe:2.3:a:mailenable:mailenable:9.82
-
cpe:2.3:a:mailenable:mailenable:9.83
-
cpe:2.3:a:mailenable:mailenable:9.84
-
cpe:2.3:a:mailenable:mailenable:9.85
-
cpe:2.3:a:mailenable:mailenable:9.86