CVE-2026-15191 Details
Description
A flaw has been found in mettle sendportal up to 3.0.1. This vulnerability affects unknown code of the file vendor/mettle/sendportal-core/src/Http/Requests/CampaignStoreRequest.php of the component Campaign Creation Endpoint. Executing a manipulation can lead to authorization bypass. The attack can be executed remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
An authorization bypass vulnerability has been identified in Mettle Sendportal versions through 3.0.1. This issue resides in the Campaign Creation Endpoint, specifically within the file 'vendor/mettle/sendportal-core/src/Http/Requests/CampaignStoreRequest.php'. The vulnerability allows users to manipulate requests in a way that bypasses authorization checks, enabling them to reference and use resources from other workspaces. The flaw can be exploited remotely, and details of the exploit have been published.
To address this vulnerability, validate that the referenced email service ID belongs to the current workspace during both the campaign creation and dispatch processes. This can be done by applying workspace-specific validation rules and checking ownership before using the email service in campaign operations.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 9, 2026CISA-ADP
Assessed Jul 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/mettle/sendportal/ | [email protected] | ProductVendor |
| https://github.com/mettle/sendportal/issues/339 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://vuldb.com/cve/CVE-2026-15191 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/851622 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/377117 | [email protected] | BundlePermission Required |
| https://vuldb.com/vuln/377117/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-285 | Improper Authorization | [email protected] |
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| mettle sendportal | <= 3.0.1 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 3, 2026 | CVE Modified | [email protected] |
| Sep 3, 2026 | CVE Modified | CISA-ADP |
| Jul 14, 2026 | CVE Modified | CISA-ADP |
| Jul 9, 2026 | New CVE Received | [email protected] |
Volerion