Sceawere

Vulnerability Detail

CVE-2026-39791UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Mailjet Sensitive Data Exposure

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
16h ago
Vendor
Mailjet
Product
Mailjet Email Marketing
Attack Type
CWE-201 Insertion of Sensitive Information Into Sent Data
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Sensitive Data Exposure in Mailjet Email Marketing <= 6.2.3 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-06T09:17:51.930Z",
  "pubdate": "2026-10-06T09:17:51.930Z",
  "executiveSummary": "The Mailjet Email Marketing plugin for WordPress, specifically versions 6.2.3 and below, contains a vulnerability that allows for unauthenticated sensitive data exposure.\nThis vulnerability is classified as an improper access control issue, enabling unauthorized actors to access information that should be protected by authentication mechanisms.\nThe flaw affects the plugin's configuration or data handling routines, exposing system or user-specific data to remote, unauthenticated attackers.\nThe primary risk implication is the potential for information disclosure, which can lead to further exploitation, such as unauthorized API key retrieval, administrative configuration compromise, or the harvesting of subscriber data.\nAttackers do not require any prior authentication or special privileges to interact with the vulnerable endpoints or components involved in the disclosure.\nSuccessful exploitation allows an adversary to gain visibility into internal plugin configurations, potentially facilitating a full takeover of the Mailjet integration within the WordPress environment.",
  "technicalDetails": "The vulnerability resides in the way the Mailjet Email Marketing plugin handles requests to certain administrative or configuration-related endpoints within versions 6.2.3 and below.\nRoot cause analysis points to insufficient or missing access control checks on specific REST API endpoints or AJAX handlers implemented by the plugin. These handlers fail to verify the authorization status of the requester, allowing unauthenticated remote users to perform GET or POST requests that result in the disclosure of sensitive data.\nIn a typical attack flow, an attacker identifies the exposed endpoint by analyzing the plugin's source code or by intercepting traffic generated by the plugin's front-end or back-end components.\nBecause the plugin does not enforce a 'capability' check (e.g., using current_user_can() in WordPress) before returning data, the vulnerable component processes the request as if it originated from a legitimate administrative user.\nThe payload generally involves crafting a direct HTTP request to the specific endpoint associated with the Mailjet plugin. When the server processes this request, it retrieves sensitive application settings, API keys, or subscriber lists from the database and returns them directly in the response body, typically in JSON format.\nThe exposure of Mailjet API keys is a critical concern, as these keys grant full programmatic access to the user's Mailjet account. With these credentials, an attacker can perform actions on behalf of the victim, such as sending phishing emails using the user's domain, deleting contact lists, or monitoring email campaign analytics.\nFurthermore, if the plugin configuration stores database credentials or internal system paths, these may also be leaked, providing the attacker with a footprint for lateral movement or deeper system exploitation.\nThe vulnerability is accessible over the network, meaning any entity with access to the website's public-facing interface can trigger the data exposure. The lack of requirement for session cookies or nonces simplifies the exploitation process for automated scanners or targeted attacks."
}
CVE-2026-39791: Mailjet Sensitive Data Exposure (MEDIUM Severity, CVSS: 5.3) | Sceawere