Security Advisory

CVE-2026-18750

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-12 21:09:15
Last updated 2026-08-13 15:47:52
Assigner certcc
CVSS score 5.3
State PUBLISHED

Description

vinny/views.py: (ModifyEmailNotifications) IDOR: view fetches VinceCommEmail by raw pk from URL and toggles email_function/name without checking the record's contact belongs to the requesting group-admin. Lets a vendor admin flip notification routing (or read email/name) for another vendor's contact.