CVE-2026-18749: Cert/cc Vince
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
The type=track branch authorises on _is_my_case(t_attach.case) only and never checks VinceTrackAttachment.shared. A coordinator-uploaded case artefact that has NOT been marked shared is still retrievable by any case member who has (or is sent) its uuid — leaks not-yet-released coordinator material to vendors on the case.
Affected products
- Cert/cc Vince: before 3.0.44 (fixed in 3.0.44)
Published 2026-08-12. Last modified 2026-09-08.