Sophia
Hart

CVE-2026-42897: OWAReaper Mailbox Persistence

Sophia Hart

Jul 30, 2026

5 min read

cve 2026 42897

TL; DR

  • CVE-2026-42897 is a Microsoft Exchange OWA cross-site scripting vulnerability reportedly exploited as a zero-day.
  • Proofpoint attributes the activity to Laundry Bear (Void Blizzard/TA488).
  • The campaign delivers OWAReaper, a browser-executed webmail backdoor.
  • Reported capabilities include OAuth token theft, mailbox permission abuse, and persistent mailbox access.
  • Remediation should extend beyond patching to include mailbox, token, and permission reviews.

CVE-2026-42897 is drawing attention because it affects Microsoft Exchange Outlook Web Access (OWA), a widely used enterprise webmail interface.

According to Proofpoint and reporting from BleepingComputer, the Russian state-sponsored threat group Laundry Bear, tracked by Microsoft as Void Blizzard and by Proofpoint as TA488, is exploiting the vulnerability to deploy OWAReaper, a browser-based backdoor designed to establish persistent access to Exchange mailboxes.

Proofpoint’s analysis indicates that OWAReaper combines mailbox permission abuse, OAuth token theft, and server-side persistence techniques that may allow access to survive password resets or endpoint replacement if the mailbox itself is not fully remediated. Organisations should independently verify whether these mechanisms were used in their own environments.

Why CVE-2026-42897 stands out

CVE-2026-42897 affects Microsoft Exchange Outlook Web Access (OWA) and is exploited within an authenticated user’s webmail session.

Proofpoint describes the vulnerability as a cross-site scripting (XSS) flaw that executes attacker-controlled JavaScript when a victim opens a specially crafted email in Outlook Web Access. Proofpoint describes the attack as a half-click exploit because the victim only needs to open the malicious email in Outlook Web Access for the JavaScript to execute.

Once the code executes within the user’s authenticated OWA session, attackers can interact with mailbox resources using the victim’s existing privileges.

How OWAReaper extends access beyond the Initial Exploit

Public reporting indicates that the exploit chain is designed to minimise visible indicators while establishing longer-term access. After execution inside the OWA reading pane, OWAReaper reportedly:

  • Removes exploit content from the message stored on the Exchange server.
  • Collects mailbox and account information.
  • Attempts credential theft using hidden browser DOM elements.
  • Obtains OAuth tokens through Outlook add-ins granted ReadWriteMailbox permissions.
  • Modifies mailbox folder permissions by assigning Owner access to the Default user.
  • Receives commands through GitHub commit messages and specially formatted emails.
  • Falls back to DNS-based exfiltration if HTTPS communication is unavailable.

Proofpoint attributes these behaviours to OWAReaper. Public reporting has not indicated that every observed compromise necessarily includes all of these capabilities.

Operational Snapshot

Observed activity Why it matters Priority
Browser-based JavaScript execution Runs inside authenticated OWA sessions High
Attempts to obtain OAuth tokens through Outlook add-ins May allow continued access after password changes High
Mailbox permission changes Can create long-term mailbox persistence High
Removal of exploit artefacts Makes incident investigation more difficult Medium
HTTPS with DNS fallback Multiple potential data exfiltration channels Medium

Why password resets may not fully remove access

One of the key reported characteristics of the campaign is its ability to establish mailbox persistence beyond credential theft.

According to Proofpoint’s analysis, attackers may establish continued access by modifying mailbox permissions and obtaining OAuth tokens through Outlook add-ins with ReadWriteMailbox permissions. If these mechanisms remain active, simply rotating passwords or rebuilding affected endpoints may not remove every avenue of access.

Rather than relying on credential resets alone, organisations should verify whether any persistence mechanisms remain in place by reviewing:

  • Mailbox folder permissions for unexpected Owner-level assignments.
  • Outlook add-ins with ReadWriteMailbox permissions.
  • Active OAuth authorisations associated with affected accounts.
  • Evidence of unauthorised mailbox changes following the suspected compromise.

Whether persistence exists in a particular environment depends on what actions were successfully completed during the compromise.

What security teams should verify

Applying Microsoft’s security updates should be the starting point rather than the end of the response. Security teams should consider reviewing:

  • Verify that affected Exchange servers are patched for CVE-2026-42897 and review endpoint patch hygiene to ensure managed devices are running current security updates.
  • Mailbox folder permissions, particularly unexpected Owner-level assignments.
  • OAuth applications and Outlook add-ins with ReadWriteMailbox permissions.
  • Exchange and OWA logs for suspicious mailbox activity.
  • Indicators of unusual outbound HTTPS or DNS communications associated with suspected compromised OWA sessions or affected endpoints.

The appropriate scope of investigation should be based on each organisation’s exposure and available forensic evidence.

How Hexnode supports enterprise response

Vendor remediation and Exchange-specific investigation remain the primary response to CVE-2026-42897. Endpoint management and visibility can complement those activities by helping organisations maintain control over managed devices that access Exchange services.

Hexnode XDR can support investigations on managed Windows endpoints by helping security teams:

  • Review endpoint incidents and device posture.
  • Review supported remote response actions available for managed Windows devices.
  • Review endpoint incidents, device posture, and endpoint events to support broader security investigations.
  • Correlate endpoint events with broader security investigations.

Hexnode UEM complements these efforts by helping administrators:

  • Enforce device compliance and restrict access to corporate resources from trusted, managed endpoints.
  • Apply endpoint security configurations and hardening policies.
  • Manage trusted corporate devices remotely.
  • Enforce browser management policies and web filtering to restrict unauthorized browser extensions and enforce secure browsing configurations across endpoints.

These capabilities support broader incident response efforts alongside Exchange remediation, mailbox auditing, and identity reviews.

The Cybersecurity Blueprint Mitre Attack Framework
Featured resource

The Cybersecurity Blueprint

Learn how to adopt the right cybersecurity strategy with practical frameworks, implementation guidance for enterprises.

DOWNLOAD

FAQs

Not necessarily. If mailbox permissions were modified or OAuth tokens were obtained through malicious Outlook add-ins, additional remediation may be required alongside a password reset.

Yes. Review installed Outlook add-ins and any granted ReadWriteMailbox permissions for unexpected or unauthorised access.

No. Incident response should also include affected user accounts, mailbox permissions, OAuth authorisations, and managed endpoints used to access OWA.

Conclusion

CVE-2026-42897 demonstrates that enterprise webmail compromise can extend beyond credential theft. Reported mailbox permission changes and OAuth token theft highlight how attackers may attempt to retain access even after password resets or endpoint remediation.

For organisations using Microsoft Exchange OWA, responding should include more than patch deployment. Reviewing mailbox permissions, OAuth authorisations, Exchange activity, and endpoint posture can help identify signs of remaining unauthorised access and strengthen remediation following exploitation of CVE-2026-42897.

Share

Sophia Hart

A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions—without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable—politely.