Description
VINCE versions 3.0.38 and earlier do not properly verify the From address authenticity due to encoding confusion and use the from address for automated actions such as Ticket creation or Ticket updates.
INFO
Published Date :
2026-05-07T19:54:49.275Z
Last Modified :
2026-05-08T13:55:16.520Z
Source :
certcc
AFFECTED PRODUCTS
The following products are affected by CVE-2026-8142 vulnerability.
No data.
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-8142.
| URL | Resource |
|---|---|
| https://github.com/CERTCC/VINCE |
|
| https://kb.cert.org/vince |
|