CVE-2026-8142
Last modified
CVE-2026-8142 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. VINCE versions 3.0.38 and earlier do not properly verify the From address authenticity due to encoding confusion and use the from address for automated actions such as Ticket creation or Ticket updates.. EPSS estimates a 0.11% chance of exploitation in the next 30 days.
Description
VINCE versions 3.0.38 and earlier do not properly verify the From address authenticity due to encoding confusion and use the from address for automated actions such as Ticket creation or Ticket updates.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| CERT/CC | VINCE | <= 3.0.38 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-8142?
How severe is CVE-2026-8142?
How do I fix CVE-2026-8142?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-8136A flaw has been found in SourceCodester Pharmacy Sales and I…2.4
- CVE-2026-8137A vulnerability has been found in Totolink X5000R 9.1.0u.636…8.8
- CVE-2026-8138A vulnerability was found in Tenda CX12L 16.03.53.12. This i…8.8
- CVE-2026-8139Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via…5.4
- CVE-2026-8140Concrete CMS 9.5.0 and below does not validate a CSRF token …6.5
- CVE-2026-8141The Ajax Load More - Filters plugin for WordPress is vulnera…7.2
- CVE-2026-8143The HBook plugin for WordPress is vulnerable to Stored Cross…7.2
- CVE-2026-8144GitLab has remediated an issue in GitLab CE/EE affecting all…4.3
- CVE-2026-8147In MLflow versions prior to 3.14.0, when running with authen…8.1
- CVE-2026-8148NAVER MYBOX Explorer for Windows before 3.0.11.160 allows a …7.8
- CVE-2026-8149A vulnerability in Legion of the Bouncy Castle Inc. BC-LTS b…5.1
- CVE-2026-8152Unblu Spark contains an open redirect vulnerability that can…9.3
Are you affected by CVE-2026-8142?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
