CVE-2026-22239
MEDIUMBLUVOYIX - Unauthenticated Email Spoofing via Email Sending API
Title source: llmDescription
The vulnerability exists in BLUVOYIX due to design flaws in the email sending API. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable email sending API. Successful exploitation of this vulnerability could allow the attacker to send unsolicited emails to anyone on behalf of the company.
References (1)
Core 1
Core References
Scores
CVSS v3
5.3
EPSS
0.0028
EPSS Percentile
19.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-400
Status
published
Products (1)
blusparkglobal/bluvoyix
Published
Jan 14, 2026
Tracked Since
Feb 18, 2026