CVE-2026-18750
CVE-2026-18750
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
vinny/views.py: (ModifyEmailNotifications) IDOR: view fetches VinceCommEmail by raw pk from URL and toggles email_function/name without checking the record's contact belongs to the requesting group-admin. Lets a vendor admin flip notification routing (or read email/name) for another vendor's contact.
| Vendor | cert/cc |
| Product | vince |
| Published | Aug 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for cert/cc vince
Be the first to know when new unknown vulnerabilities affecting cert/cc vince are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
CERT/CC / VINCE
0 < 3.0.44