The vulnerability exists in BLUVOYIX due to design flaws in the email sending API. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable email sending API. Successful exploitation of this vulnerability could allow the attacker to send unsolicited emails to anyone on behalf of the company.
References
| Link | Resource |
|---|---|
| https://blusparkglobal.com/bluvoyix/ | Product |
Configurations
History
02 Feb 2026, 15:50
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Blusparkglobal bluvoyix
Blusparkglobal |
|
| References | () https://blusparkglobal.com/bluvoyix/ - Product | |
| CWE | NVD-CWE-noinfo | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
| CPE | cpe:2.3:a:blusparkglobal:bluvoyix:-:*:*:*:*:*:*:* |
14 Jan 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-14 15:16
Updated : 2026-02-02 15:50
NVD link : CVE-2026-22239
Mitre link : CVE-2026-22239
CVE.ORG link : CVE-2026-22239
JSON object : View
Products Affected
blusparkglobal
- bluvoyix
CWE
