PT-2026-56868 · Git+1 · Sendportal

·

CVE-2026-15192

·

Published

2026-07-09

·

Updated

2026-09-03

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions mettle sendportal versions prior to 3.0.2
Description An issue in the APIv1 Webhooks component allows remote attackers to bypass authentication. This occurs within the sendgrid/postmark/postal/mailjet functions, where improper manipulation leads to missing authentication.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the sendgrid/postmark/postal/mailjet functions within the APIv1 Webhooks component.

Exploit

Missing Authentication

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15192

Affected Products

Sendportal