CVE-2026-7145
mettle sendportal Invitation WorkspaceInvitationsController.php destroy authorization
CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th
A weakness has been identified in mettle sendportal up to 3.0.1. Affected is the function destroy of the file app/Http/Controllers/Workspaces/WorkspaceInvitationsController.php of the component Invitation Handler. This manipulation of the argument invitation causes authorization bypass. The attack may be initiated remotely. The project was informed of the problem early through an issue report but has not responded yet.
| CWE | CWE-639 CWE-285 |
| Vendor | mettle |
| Product | sendportal |
| Published | Apr 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for mettle sendportal
Be the first to know when new medium vulnerabilities affecting mettle sendportal are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:X/RL:X/RC:R Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
mettle / sendportal
3.0.0 3.0.1
References
Credits
๐ B1scuit (VulDB User) VulDB CNA Team