CVE-2026-18744: Security vulnerability
Any authenticated case participant can fetch any OTHER vendor's CaseStatement + per-vul CaseMemberStatus by supplying that member's id — testfunc only checks ismycase, not ownership of kwargs['member']. Bypasses sharestatus; leaks embargoed vendor affected/not-affected + statement text cross-tenant.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18744?
CVE-2026-18744 has a risk score of 57, indicating a moderate level of vulnerability.
How do I fix CVE-2026-18744?
To fix CVE-2026-18744, ensure that case statements and member statuses are only accessible by authorized participants based on ownership checks.
Who is affected by CVE-2026-18744?
Any authenticated case participant can be affected by CVE-2026-18744 as they can potentially access confidential information from other vendors.
What data is leaked due to CVE-2026-18744?
CVE-2026-18744 can leak embargoed vendor statuses and case statement texts, compromising sensitive information.
When was CVE-2026-18744 published?
CVE-2026-18744 was published on August 12, 2026.