IDOR Vulnerability in Vince Communication Application by CERTCC
CVE-2026-18750
Currently unrated
What is CVE-2026-18750?
The Vince Communication Application has a vulnerability that allows an authorized vendor admin to access and modify notifications related to other vendor's contacts. This occurs when the application fetches email notifications based solely on a raw primary key from the URL, without validating if the contact belongs to the requesting group-admin. This oversight can lead to unauthorized email routing and potential data leakage, compromising the privacy and integrity of vendor communications.
Affected Version(s)
VINCE 0 < 3.0.44
