Unauthorized Access Vulnerability in VINCE by CERTCC
CVE-2026-18744

Currently unrated

Key Information:

Vendor

Cert/cc

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-18744?

An authenticated participant within the VINCE platform can exploit a vulnerability to retrieve sensitive information related to other vendors’ CaseStatements and CaseMemberStatuses. The vulnerability occurs due to inadequate checks in the test_func function, which only verifies the participant's association with their own case, neglecting proper ownership verification of the 'member' parameters. This oversight allows unauthorized data access, leading to potential leaks of confidential vendor information across tenant boundaries.

Affected Version(s)

VINCE 0 < 3.0.44

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.