IDOR Vulnerability in Vince Communication Application by CERTCC
CVE-2026-18750

Currently unrated

Key Information:

Vendor

Cert/cc

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-18750?

The Vince Communication Application has a vulnerability that allows an authorized vendor admin to access and modify notifications related to other vendor's contacts. This occurs when the application fetches email notifications based solely on a raw primary key from the URL, without validating if the contact belongs to the requesting group-admin. This oversight can lead to unauthorized email routing and potential data leakage, compromising the privacy and integrity of vendor communications.

Affected Version(s)

VINCE 0 < 3.0.44

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.