RSS: MailEnable Premium Vulnerability


A vulnerability in MailEnable Enterprise Premium versions 10.55 and earlier has been identified that may allow authorized users to reset the passwords of other users in the same postoffice if mobile webadmin is accessible. Standard, Professional and Enterprise Editions are not affected.


Enterprise Premium Version 10 installations should be upgraded to Version 10.56 or later.

Enterprise Premium Version 9 installations should be upgraded to Version 9.89 or later.

Enterprise Premium Version 8 installations should be upgraded to Version 8.70 or later.

Thanks to dninh for the discovery of this.


MORE INFORMATION

Version 10 Premium users can download the update from: https://www.mailenable.com/download.asp.

If your version is prior to version 10, then you can download the update from: https://www.mailenable.com/downloadprevious.asp.


Product: MailEnable
Version: All Versions
Revision Date: Wed, 18 Mar 2026 08:16:56 -0400