CVE-2026-18749: Track vulnerability
The type=track branch authorises on ismycase(tattach.case) only and never checks VinceTrackAttachment.shared. A coordinator-uploaded case artefact that has NOT been marked shared is still retrievable by any case member who has (or is sent) its uuid — leaks not-yet-released coordinator material to vendors on the case.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18749?
The severity of CVE-2026-18749 is rated as 33.
How do I fix CVE-2026-18749?
To fix CVE-2026-18749, ensure that the authorization check includes validation for VinceTrackAttachment.shared.
What type of vulnerability is CVE-2026-18749?
CVE-2026-18749 is a vulnerability related to unauthorized retrieval of case artifacts due to insufficient access controls.
Who is affected by CVE-2026-18749?
Users who are members of a case without proper authorization checks for shared attachments are affected by CVE-2026-18749.
What can be the potential impact of CVE-2026-18749?
The potential impact of CVE-2026-18749 includes unintended access to sensitive coordinator materials by unauthorized case members.