Security Advisory

CVE-2026-18749

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-12 21:10:19
Last updated 2026-08-13 15:46:38
Assigner certcc
CVSS score 9.8
State PUBLISHED

Description

The type=track branch authorises on _is_my_case(t_attach.case) only and never checks VinceTrackAttachment.shared. A coordinator-uploaded case artefact that has NOT been marked shared is still retrievable by any case member who has (or is sent) its uuid — leaks not-yet-released coordinator material to vendors on the case.