VINCE versions 3.0.38 and earlier do not properly verify the From address authenticity due to encoding confusion and use the from address for automated actions such as Ticket creation or Ticket updates.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://github.com/CERTCC/VINCE |
|
| https://kb.cert.org/vince |
|
History
Fri, 08 May 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 CWE-284 |
Fri, 08 May 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 07 May 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 CWE-284 |
Thu, 07 May 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | VINCE versions 3.0.38 and earlier do not properly verify the From address authenticity due to encoding confusion and use the from address for automated actions such as Ticket creation or Ticket updates. | |
| Title | CVE-2026-8142 | |
| References |
|
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2026-05-08T13:55:16.520Z
Reserved: 2026-05-07T19:50:29.029Z
Link: CVE-2026-8142
Updated: 2026-05-08T13:55:12.360Z
Status : Awaiting Analysis
Published: 2026-05-07T20:16:45.670
Modified: 2026-05-08T14:16:48.823
Link: CVE-2026-8142
No data.
OpenCVE Enrichment
Updated: 2026-05-08T21:15:05Z