CVE-2026-42193 Details
Description
Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, the /webhooks/sns endpoint accepts Amazon SNS notification payloads from unauthenticated requests without verifying the SNS signature, certificate, or topic ARN, meaning anyone can forge a valid-looking webhook request. This allows an unauthenticated attacker to spoof SNS events to trigger workflow automations, unsubscribe contacts, manipulate email delivery metrics, and potentially exhaust billing credits. This issue has been patched in version 0.9.0.
A vulnerability exists in Plunk, an open-source email platform that utilizes AWS SES, in versions prior to 0.9.0. The issue arises in the /webhooks/sns endpoint, which processes Amazon SNS notification payloads from unauthenticated requests without proper verification of the SNS signature, certificate, or topic ARN. This lack of validation allows anyone to forge a webhook request that appears legitimate. As a result, an unauthenticated attacker could spoof SNS events to trigger workflow automations, unsubscribe contacts, manipulate email delivery metrics, and potentially deplete billing credits.
Users can upgrade to Plunk version 0.9.0 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 8, 2026CISA-ADP
Assessed May 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/useplunk/plunk/releases/tag/v0.9.0 | [email protected] | Release NotesVendor |
| https://github.com/useplunk/plunk/security/advisories/GHSA-9792-w86v-gx53 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-347 | Improper Verification of Cryptographic Signature | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| useplunk plunk | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 8, 2026 | New CVE Received | [email protected] |
Volerion