---
id: CVE-2026-15192
title: A vulnerability has been found in mettle sendportal up to 3.0.1
summary: >-
  A vulnerability has been found in mettle sendportal up to 3.0.1. This issue
  affects the function sendgrid/postmark/postal/mailjet of the component APIv1
  Webhooks. The manipulation leads to missing authentication. The attack is
  possible t…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'
cwe:
  - CWE-287
  - CWE-306
published: '2026-07-09'
updated: '2026-09-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15192'
references:
  - url: 'https://github.com/mettle/sendportal/'
    label: cna@vuldb.com
  - url: 'https://github.com/mettle/sendportal/issues/340'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-15192'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/851624'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/377118'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/377118/cti'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00763
epssPercentile: 0.53401
ingestedAt: '2026-09-04T04:14:25.183Z'
---

## Overview

A vulnerability has been found in mettle sendportal up to 3.0.1. This issue affects the function sendgrid/postmark/postal/mailjet of the component APIv1 Webhooks. The manipulation leads to missing authentication. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
