The vulnerability exists in BLUVOYIX due to design flaws in the email sending API. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable email sending API. Successful exploitation of this vulnerability could allow the attacker to send unsolicited emails to anyone on behalf of the company.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://blusparkglobal.com/bluvoyix/ |
|
History
Wed, 14 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 14 Jan 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The vulnerability exists in BLUVOYIX due to design flaws in the email sending API. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable email sending API. Successful exploitation of this vulnerability could allow the attacker to send unsolicited emails to anyone on behalf of the company. | |
| Title | Email Sending Vulnerability in BLUVOYIX | |
| Weaknesses | CWE-400 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: MHV
Published:
Updated: 2026-01-14T14:56:01.047Z
Reserved: 2026-01-06T23:20:59.365Z
Link: CVE-2026-22239
Updated: 2026-01-14T14:55:55.773Z
Status : Awaiting Analysis
Published: 2026-01-14T15:16:05.260
Modified: 2026-01-14T16:25:12.057
Link: CVE-2026-22239
No data.
OpenCVE Enrichment
No data.