CVE-2026-18750: Cert/cc Vince
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
vinny/views.py: (ModifyEmailNotifications) IDOR: view fetches VinceCommEmail by raw pk from URL and toggles email_function/name without checking the record's contact belongs to the requesting group-admin. Lets a vendor admin flip notification routing (or read email/name) for another vendor's contact.
Affected products
- Cert/cc Vince: before 3.0.44 (fixed in 3.0.44)
Published 2026-08-12. Last modified 2026-09-08.