CVE-2026-8142

MEDIUM

VINCE <= 3.0.38 - Email Spoofing via From Address Encoding Confusion

Title source: llm
STIX 2.1

Description

VINCE versions 3.0.38 and earlier do not properly verify the From address authenticity due to encoding confusion and use the from address for automated actions such as Ticket creation or Ticket updates.

References (2)

Core 2

Scores

CVSS v3 6.5
EPSS 0.0011
EPSS Percentile 1.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

Status published
Products (1)
CERT/CC/VINCE < 3.0.38
Published May 07, 2026
Tracked Since May 08, 2026