Authentication Flaw in simalexan API Gateway Endpoint Affecting Email Functionality
CVE-2026-90513

6.9MEDIUM

Key Information:

Vendor

Simalexan

Vendor
CVE Published:
13 September 2026

What is CVE-2026-90513?

A vulnerability has been identified in the simalexan api-lambda-send-email-ses product affecting the SES.sendEmail function within the API Gateway Endpoint component. This flaw arises from improper handling of parameters, including toEmails, ccEmails, replyToEmails, subject, and message, leading to a lack of necessary authentication. The issue allows potential attackers to exploit this vulnerability remotely. Due to the product's rolling release model, detailed versioning information on affected or patched releases remains unavailable. Despite early notification of this issue through an issue report, the project maintainers have yet to provide a response.

Affected Version(s)

api-lambda-send-email-ses bda6869aa81371d1e872242e74fe7d953edb818d

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

changli (VulDB User)
VulDB CNA Team
.