The type=track branch authorises on _is_my_case(t_attach.case) only and never checks VinceTrackAttachment.shared. A coordinator-uploaded case artefact that has NOT been marked shared is still retrievable by any case member who has (or is sent) its uuid — leaks not-yet-released coordinator material to vendors on the case.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 13 Aug 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cert
Cert vince |
|
| Vendors & Products |
Cert
Cert vince |
Thu, 13 Aug 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 CWE-285 |
Wed, 12 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The type=track branch authorises on _is_my_case(t_attach.case) only and never checks VinceTrackAttachment.shared. A coordinator-uploaded case artefact that has NOT been marked shared is still retrievable by any case member who has (or is sent) its uuid — leaks not-yet-released coordinator material to vendors on the case. | |
| Title | CVE-2026-18749 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2026-08-12T21:10:19.828Z
Reserved: 2026-08-03T21:27:40.008Z
Link: CVE-2026-18749
No data.
Status : Received
Published: 2026-08-12T22:17:14.933
Modified: 2026-08-12T22:17:14.933
Link: CVE-2026-18749
No data.
OpenCVE Enrichment
Updated: 2026-08-13T10:15:07Z