CVE-2026-18744: Cert/cc Vince

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Any authenticated case participant can fetch any OTHER vendor's CaseStatement + per-vul CaseMemberStatus by supplying that member's id — test_func only checks _is_my_case, not ownership of kwargs['member']. Bypasses share_status; leaks embargoed vendor affected/not-affected + statement text cross-tenant.

Affected products

  • Cert/cc Vince: before 3.0.44 (fixed in 3.0.44)

Published 2026-08-12. Last modified 2026-09-08.