PatchSiren cyber security CVE debrief
CVE-2026-75872 maalfer CVE debrief
The CVE-2026-75872 record details an HTML injection vulnerability in the public subscription form of MailerUp before version 1.1.3. This vulnerability allows unauthenticated remote attackers to inject arbitrary HTML content into the double opt-in verification email by manipulating the first_name field of the subscription request. Organizations using MailerUp for email subscriptions, especially those with public subscription forms, should be aware of this vulnerability and take steps to mitigate it. The CVE record was published on 2026-08-18T15:17:15.150Z and has not been modified since then. To address this vulnerability, it is crucial to understand the potential impact on affected systems and to apply the necessary patches or mitigations.
- Vendor
- maalfer
- Product
- MailerUp
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-18
- Original CVE updated
- 2026-09-01
- Advisory published
- 2026-08-18
- Advisory updated
- 2026-09-01
Who should care
Organizations using MailerUp for email subscriptions, especially those with public subscription forms, should be aware of this vulnerability and take steps to mitigate it. This includes reviewing and updating MailerUp installations to ensure they are running a patched version, monitoring email subscriptions for suspicious activity, and educating users about the potential risks associated with this vulnerability. IT teams and security professionals responsible for managing MailerUp installations should prioritize patching and implement compensating controls where necessary to prevent exploitation of this vulnerability. Furthermore, security teams should review the vulnerability's potential impact on their organization's assets and implement measures to minimize risk, such as restricting access to sensitive areas of the system and enhancing monitoring and detection capabilities. By taking these steps, organizations can reduce the risk of exploitation and protect their systems and data from potential harm. The vulnerability's impact can be significant, and proactive measures are essential to prevent potential security breaches. Therefore, it is crucial for organizations to address this vulnerability promptly and thoroughly to ensure the security and integrity of their systems and data. MailerUp users should also consider implementing additional security measures, such as input validation and content filtering, to further reduce the risk of exploitation. By prioritizing patching and implementing compensating controls, organizations can minimize the risk of exploitation and protect their systems and data from potential harm. The vulnerability's severity and potential impact emphasize the need for prompt action to prevent potential security breaches. Organizations should not delay in addressing this vulnerability and should take immediate action to protect their systems and data. The importance of addressing this vulnerability cannot be overstated, and organizations must take proactive measures to prevent potential security breaches. To ensure the security and integrity of their systems and data, organizations must prioritize patching and implement compensating to '
Technical summary
The public subscription form in MailerUp before version 1.1.3 is vulnerable to HTML injection. An unauthenticated remote attacker can inject arbitrary HTML content into the double opt-in verification email by manipulating the first_name field of the subscription request. This vulnerability can lead to potential security risks, including the sending of malicious emails. Organizations should review their MailerUp installations and ensure they are running a patched version to prevent potential HTML injection attacks. Additionally, monitoring email subscriptions for suspicious activity can help detect and mitigate the effects of this vulnerability.
Defensive priority
Organizations using MailerUp before version 1.1.3 should prioritize patching to prevent potential HTML injection attacks.
Recommended defensive actions
- Apply the patch from version 1.1.3 or later
- Review and update MailerUp installations to ensure they are running a patched version
- Monitor email subscriptions for suspicious activity
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE description indicates that HTML injection is possible in the public subscription form of MailerUp before version 1.1.3, allowing unauthenticated remote attackers to send emails with arbitrary HTML content.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-75872 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-75872
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-75872 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75872
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/maalfer/mailerup/commit/da4aedc9621911df4ce0cc8f0b321dd6d10f40a5
4daa8cea-433a-44bd-9456-53b127fc289a
-
Source reference
Unverified legacy reference
URL: https://github.com/maalfer/mailerup/releases/tag/v1.1.3
4daa8cea-433a-44bd-9456-53b127fc289a
-
Source reference
Unverified legacy reference
URL: https://secur0.com/en/cna/cve-list/cve-2026-75872-html-injection-in-mailerup-double-optin-verification-email
4daa8cea-433a-44bd-9456-53b127fc289a
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.