Data Exposure Vulnerability in Vince by CERTCC
CVE-2026-18749
Currently unrated
What is CVE-2026-18749?
A security flaw exists within the Vince system, where certain case artifacts uploaded by coordinators can be accessed by case members without proper authorization checks. Specifically, the '_is_my_case(t_attach.case)' function fails to verify if the associated attachments marked as non-shared can still be retrieved using their UUIDs. This oversight poses a risk of sensitive and unreleased information being exposed to unauthorized vendors within the case ecosystem.
Affected Version(s)
VINCE 0 < 3.0.44
