CVE-2026-8142

VINCE versions 3.0.38 and earlier do not properly verify the From address authenticity due to encoding confusion and use the from address for automated actions such as Ticket creation or Ticket updates.
Configurations

No configuration.

History

08 May 2026, 14:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

07 May 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-07 20:16

Updated : 2026-06-17 11:03


NVD link : CVE-2026-8142

Mitre link : CVE-2026-8142

CVE.ORG link : CVE-2026-8142


JSON object : View

Products Affected

No product.

CWE

No CWE.