{"id":"CVE-2026-18749","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-18749","summary":"The type=track branch authorises on _is_my_case(t_attach.case) only and never checks VinceTrackAttachment.shared. A coordinator-uploaded case artefact that has NOT been marked shared…","details":"The type=track branch authorises on _is_my_case(t_attach.case) only and never checks VinceTrackAttachment.shared. A coordinator-uploaded case artefact that has NOT been marked shared is still retrievable by any case member who has (or is sent) its uuid — leaks not-yet-released coordinator material to vendors on the case.","published":"2026-08-12T22:17:14.933","modified":"2026-08-13T16:17:58.987","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/CERTCC/VINCE/pull/235","label":"CERTCC/VINCE#235"},"references":[{"type":"WEB","url":"https://github.com/CERTCC/VINCE"},{"type":"WEB","url":"https://github.com/CERTCC/VINCE/pull/235"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-13T16:17:58.987"}}