CVE-2026-18744
CVE-2026-18744
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Any authenticated case participant can fetch any OTHER vendor's CaseStatement + per-vul CaseMemberStatus by supplying that member's id โ test_func only checks _is_my_case, not ownership of kwargs['member']. Bypasses share_status; leaks embargoed vendor affected/not-affected + statement text cross-tenant.
| Vendor | cert/cc |
| Product | vince |
| Published | Aug 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for cert/cc vince
Be the first to know when new unknown vulnerabilities affecting cert/cc vince are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
CERT/CC / VINCE
0 < 3.0.44