Unauthenticated Webhook Vulnerability in Plunk by UsePlunk
CVE-2026-42193

9.1CRITICAL

Key Information:

Vendor

Useplunk

Status
Vendor
CVE Published:
8 May 2026

What is CVE-2026-42193?

Plunk, an open-source email platform leveraging Amazon Simple Email Service (SES), contains a vulnerability in its /webhooks/sns endpoint that permits unauthenticated requests. Prior to version 0.9.0, the absence of verification for Amazon SNS signatures, certificates, and topic ARNs enabled unauthorized users to spoof valid webhook notifications. This vulnerability potentially allows attackers to manipulate workflow automations, unsubscribe contacts, and skew email delivery metrics, thus risking significant financial implications through billing credit depletion. The issue has been rectified in version 0.9.0.

Affected Version(s)

plunk < 0.9.0

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.