6.5
CVE-2026-8142
- EPSS 0.12%
- Veröffentlicht 07.05.2026 19:54:49
- Zuletzt bearbeitet 08.05.2026 14:16:48
- Quelle cret@cert.org
- CVE-Watchlists
- Unerledigt
CVE-2026-8142
VINCE versions 3.0.38 and earlier do not properly verify the From address authenticity due to encoding confusion and use the from address for automated actions such as Ticket creation or Ticket updates.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerCERT/CC
≫
Produkt
VINCE
Version <=
3.0.38
Version
*
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.12% | 0.018 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 6.5 | 3.9 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
|
https://kb.cert.org/vince
https://github.com/CERTCC/VINCE