Description
A flaw has been found in simalexan api-lambda-send-email-ses up to bda6869aa81371d1e872242e74fe7d953edb818d. This issue affects the function SES.sendEmail of the file template.yml of the component API Gateway Endpoint. This manipulation of the argument toEmails/ccEmails/replyToEmails/subject/message causes missing authentication. It is possible to initiate the attack remotely. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-13
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authentication bypass
Action: Apply Workaround
AI Analysis

Impact

The flaw disables authentication checks on the SES.sendEmail Lambda function’s email parameters—recipient addresses, cc, reply‑to, subject, and message—allowing unauthenticated users to invoke the endpoint and send arbitrary emails. The resulting impact is moderate, reflected by a CVSS score of 6.9, and could enable phishing, spam, or other malicious email campaigns by an attacker.

Affected Systems

The vulnerable component is simalexan’s api‑lambda‑send‑email‑ses. It follows a rolling‑release model and specific affected commit ranges are not published, so any active deployment may be susceptible until a fix is released.

Risk and Exploitability

The vulnerability is exploitable remotely through the API Gateway endpoint; no authentication is required to invoke the function. The CVSS score of 6.9 indicates less than 1 % suggests a low likelihood of widespread exploitation, and the issue is not listed in the CISA KEV catalog. An attacker with network access to the Gateway could send arbitrary emails to any address, potentially compromising confidentiality, integrity, or availability of the email system.

Generated by OpenCVE AI on September 15, 2026 at 17:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Enable IAM authentication or an API key on the API Gateway endpoint to restrict access to authorized callers.
  • Add a Lambda authorizer or resource policy that verifies caller identity before executing the function.
  • Implement input validation in the Lambda to whitelist acceptable recipient addresses and reject all others.
  • Configure CloudWatch logs and set alerts on outbound email volume to detect abnormal activity.

Generated by OpenCVE AI on September 15, 2026 at 17:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description A flaw has been found in simalexan api-lambda-send-email-ses up to bda6869aa81371d1e872242e74fe7d953edb818d. This issue affects the function SES.sendEmail of the file template.yml of the component API Gateway Endpoint. This manipulation of the argument toEmails/ccEmails/replyToEmails/subject/message causes missing authentication. It is possible to initiate the attack remotely. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Title simalexan api-lambda-send-email-ses API Gateway Endpoint template.yml SES.sendEmail missing authentication
First Time appeared Simalexan
Simalexan api-lambda-send-email-ses
Weaknesses CWE-287
CWE-306
CPEs cpe:2.3:a:simalexan:api-lambda-send-email-ses:*:*:*:*:*:*:*:*
Vendors & Products Simalexan
Simalexan api-lambda-send-email-ses
References
Metrics cvssV2_0

{'score': 6.4, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:P/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Simalexan Api-lambda-send-email-ses
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T16:24:01.118Z

Reserved: 2026-09-12T09:23:22.185Z

Link: CVE-2026-90513

cve-icon Vulnrichment

Updated: 2026-09-14T16:23:58.050Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T11:17:00.237

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90513

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:00:17Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function