CVE 6.5 MEDIUM

CVE-2026-8142_CVE-2026-8142

6.5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Description

VINCE versions 3.0.38 and earlier do not properly verify the From address authenticity due to encoding confusion and use the from address for automated actions such as Ticket creation or Ticket updates.

Basic Information

ID CVE-2026-8142
Source certcc
Published May 7, 2026 at 19:54
Modified May 8, 2026 at 13:55

Affected Product

Vendor CERT/CC
Product VINCE
Affected Versions CERT/CC VINCE 0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.