CVE-2026-15191

MEDIUM

mettle sendportal Campaign Creation Endpoint CampaignStoreRequest.php authorization

Title source: cna
STIX 2.1

Description

A flaw has been found in mettle sendportal up to 3.0.1. This vulnerability affects unknown code of the file vendor/mettle/sendportal-core/src/Http/Requests/CampaignStoreRequest.php of the component Campaign Creation Endpoint. Executing a manipulation can lead to authorization bypass. The attack can be executed remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

References (6)

Core 6
Core References
Vdb Entry vdb-entry
VDB-377117 | mettle sendportal Campaign Creation Endpoint CampaignStoreRequest.php authorization
https://vuldb.com/vuln/377117
Signature, Permissions Required signature permissions-required
VDB-377117 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/377117/cti
Third Party Advisory third-party-advisory
CVE-2026-15191 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-15191
Third Party Advisory third-party-advisory
Submit #851622 | Mettle SendPortal Latest Authorization Bypass
https://vuldb.com/submit/851622
Exploit exploit issue-tracking
https://github.com/mettle/sendportal/issues/339

Scores

CVSS v3 6.3
EPSS 0.0022
EPSS Percentile 12.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-285 CWE-639
Status published
Products (2)
mettle/sendportal 3.0.0
mettle/sendportal 3.0.1
Published Jul 09, 2026
Tracked Since Jul 09, 2026