Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-18749: VinceTrack Attachment Leaks Coordinator Material

CVE-2026-18749 · published 22 days ago
Summary

The VinceTrack software has a flaw that allows unauthorized access to sensitive case information. This can happen when a coordinator uploads a case artefact that is not shared, but is still accessible to case members who have the artefact's unique identifier. To protect sensitive information, ensure that all case artefacts are properly shared or restricted to authorized users.

What to do
  • Update cert/cc vince to version 3.0.44 or later.
Affected software
VendorProductAffected versions
cert/cc vince < 3.0.44
Original advisory text
CVE-2026-18749
The type=track branch authorises on _is_my_case(t_attach.case) only and never checks VinceTrackAttachment.shared. A coordinator-uploaded case artefact that has NOT been marked shared is still retrievable by any case member who has (or is sent) its uuid — leaks not-yet-released coordinator material to vendors on the case.
Severity
9.8 Critical
Exploitation
EPSS <1%
Type
CWE-639Authorization Bypass Through User-Controlled Key
Timeline
Published12 Aug 2026
Updated30 Aug 2026
First seen12 Aug 2026
Sources
CVE-2026-18749 · MITRE
Monitor software like this
Free during beta