CVE-2026-48780: Forem vulnerable to bypass of email address domain restrictions

Published Jun 16, 2026
·
Updated

Forem is open source software for building communities. Prior to commit a2ab6d4, a maliciously crafted email address could allow an attacker to bypass domain allowlist or denylist restrictions and gain access to invite-only forem deployments. The issue is patched as of a2ab6d4. As a workaround, some SMTP servers and email delivery providers may drop or refuse to send maliciously crafted email addresses.

Affected Software

1 affected component
forem forem<a2ab6d4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Patch a2ab6d4
  2. Compensating control

    Configure your SMTP server or email delivery provider to drop or refuse to send/accept maliciously crafted email addresses (i.e., reject malformed addresses) as a temporary workaround until the Forem code is patched with commit a2ab6d4.

Event History

Jun 16, 2026
CVE Published
via MITRE·02:10 PM
Data Sourced
via MITRE·02:10 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-48780?

The severity of CVE-2026-48780 is rated as high with a score of 8.2.

2

How do I fix CVE-2026-48780?

CVE-2026-48780 can be fixed by updating to the patched version following commit a2ab6d4.

3

What exploit does CVE-2026-48780 enable?

CVE-2026-48780 allows an attacker to bypass email address domain restrictions, potentially gaining access to invite-only Forem deployments.

4

What type of software is affected by CVE-2026-48780?

CVE-2026-48780 affects the Forem open-source software used for building communities.

5

What should I do if I cannot immediately update to patch CVE-2026-48780?

If you cannot update immediately, consider implementing a workaround by reviewing and tightening domain allowlist or denylist settings.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203