Data Exposure Vulnerability in Vince by CERTCC
CVE-2026-18749

Currently unrated

Key Information:

Vendor

Cert/cc

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-18749?

A security flaw exists within the Vince system, where certain case artifacts uploaded by coordinators can be accessed by case members without proper authorization checks. Specifically, the '_is_my_case(t_attach.case)' function fails to verify if the associated attachments marked as non-shared can still be retrieved using their UUIDs. This oversight poses a risk of sensitive and unreleased information being exposed to unauthorized vendors within the case ecosystem.

Affected Version(s)

VINCE 0 < 3.0.44

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.