VINCE versions 3.0.38 and earlier do not properly verify the From address authenticity due to encoding confusion and use the from address for automated actions such as Ticket creation or Ticket updates.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://github.com/CERTCC/VINCE |
|
| https://kb.cert.org/vince |
|
History
Thu, 07 May 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 CWE-284 |
Thu, 07 May 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | VINCE versions 3.0.38 and earlier do not properly verify the From address authenticity due to encoding confusion and use the from address for automated actions such as Ticket creation or Ticket updates. | |
| Title | CVE-2026-8142 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2026-05-07T19:54:49.275Z
Reserved: 2026-05-07T19:50:29.029Z
Link: CVE-2026-8142
No data.
Status : Awaiting Analysis
Published: 2026-05-07T20:16:45.670
Modified: 2026-05-07T20:32:47.823
Link: CVE-2026-8142
No data.
OpenCVE Enrichment
Updated: 2026-05-07T21:30:25Z