Junglewise Threat Intelligence

CVE-2026-13164: MailerUp unauthenticated self-registration in RegisterView

CVE-2026-13164 · Severity: info · CVSS 8.8 · Published 2026-06-24

Executive brief

MailerUp is an email marketing and automation platform. A security flaw in its registration system allows anyone on the internet to create a new account without permission, even if the administrator has disabled public registration. Once an attacker creates an account, they can gain unauthorized access to all emails stored on the system, leading to a total breach of sensitive communication data.

Technical details

A Missing Authentication for Critical Function (CWE-306) vulnerability exists in the `RegisterView` component of MailerUp, specifically at the `POST /api/auth/register/` endpoint. The endpoint was configured with the `AllowAny` permission and lacked secondary controls such as email verification, CAPTCHA, or administrative approval workflows. A remote, unauthenticated attacker can exploit this to create a valid account on instances where registration is intended to be restricted. Once registered, the attacker can access and read all email data stored within the instance. This issue is resolved in version 1.0.1 by removing the public registration endpoint and requiring administrative creation of new accounts.

Affected products

  • MailerUp MailerUp < 1.0.1

Timeline

  • 2026-06-23: patched: Fix committed to GitHub repository.
  • 2026-06-24: disclosed: Vulnerability published by Secur0 CNA.
  • 2026-06-24: advisory: NVD record published.

References

Related threats