CVE-2026-8142
CVE-2026-8142
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
VINCE versions 3.0.38 and earlier do not properly verify the From address authenticity due to encoding confusion and use the from address for automated actions such as Ticket creation or Ticket updates.
| Vendor | cert/cc |
| Product | vince |
| Published | May 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for cert/cc vince
Be the first to know when new unknown vulnerabilities affecting cert/cc vince are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
CERT/CC / VINCE
0 โค 3.0.38
References
Credits
Thanks to Guillem Lefait [email protected] for reporting the issue