CVE-2026-15192

MEDIUM

mettle sendportal APIv1 Webhooks mailjet missing authentication

Title source: cna
STIX 2.1

Description

A vulnerability has been found in mettle sendportal up to 3.0.1. This issue affects the function sendgrid/postmark/postal/mailjet of the component APIv1 Webhooks. The manipulation leads to missing authentication. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

References (6)

Core 6
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-377118 | mettle sendportal APIv1 Webhooks mailjet missing authentication
https://vuldb.com/vuln/377118
Signature, Permissions Required signature permissions-required
VDB-377118 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/377118/cti
Third Party Advisory third-party-advisory
CVE-2026-15192 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-15192
Third Party Advisory third-party-advisory
Submit #851624 | Mettle sendportal Latest Improper Authentication
https://vuldb.com/submit/851624
Exploit exploit issue-tracking
https://github.com/mettle/sendportal/issues/340

Scores

CVSS v3 6.5
EPSS 0.0057
EPSS Percentile 44.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-287 CWE-306
Status published
Products (2)
mettle/sendportal 3.0.0
mettle/sendportal 3.0.1
Published Jul 09, 2026
Tracked Since Jul 09, 2026