Unauthenticated Access Vulnerability in Appriss Insights Applications
CVE-2026-63359

9.3CRITICAL

What is CVE-2026-63359?

The Appriss Insights applications, utilized by Equifax for their Victim Information Notification Exchange (VINE), present a significant security flaw. An unauthenticated attacker has the capability to exploit this vulnerability by sending specially-crafted requests. This allows them to bypass the login mechanism, potentially gaining access to other users' accounts, sensitive personal identifiable information (PII), and confidential data stored within the database. Such unauthorized access can lead to severe repercussions for individuals affected by data breaches.

Affected Version(s)

Victim Information Notification Exchange (VINE) *

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adam Rose, CISA
.