{"id":"CVE-2026-18750","title":"vinny/views.py: (ModifyEmailNotifications)\tIDOR: view fetches VinceCommEmail by raw pk from URL and toggles email_function/name without checking the record's contact belongs to the requesting group-admin","summary":"vinny/views.py: (ModifyEmailNotifications)\tIDOR: view fetches VinceCommEmail by raw pk from URL and toggles email_function/name without checking the record's contact belongs to the requesting group-admin. Lets a vendor admin flip notific…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-639"],"published":"2026-08-12","updated":"2026-09-08","sourceUpdated":"2026-09-08T14:07:24.140","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-18750","references":[{"url":"https://certcc.github.com/CERTCC/VINCE/","label":"cret@cert.org"},{"url":"https://github.com/CERTCC/VINCE/pull/235","label":"cret@cert.org"}],"tags":["nvd"],"epss":0.00325,"epssPercentile":0.22815,"ingestedAt":"2026-09-08T15:33:26.953Z","slug":"CVE-2026-18750","body":"## Overview\n\nvinny/views.py: (ModifyEmailNotifications)\tIDOR: view fetches VinceCommEmail by raw pk from URL and toggles email_function/name without checking the record's contact belongs to the requesting group-admin. Lets a vendor admin flip notification routing (or read email/name) for another vendor's contact.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}