CVE-2026-8142: Cert/cc Vince

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

VINCE versions 3.0.38 and earlier do not properly verify the From address authenticity due to encoding confusion and use the from address for automated actions such as Ticket creation or Ticket updates.

Affected products

  • Cert/cc Vince: up to and including 3.0.38

Published 2026-05-07. Last modified 2026-06-17.