CVE-2026-18750

vinny/views.py: (ModifyEmailNotifications) IDOR: view fetches VinceCommEmail by raw pk from URL and toggles email_function/name without checking the record's contact belongs to the requesting group-admin. Lets a vendor admin flip notification routing (or read email/name) for another vendor's contact.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-12 22:17

Updated : 2026-09-08 14:07


NVD link : CVE-2026-18750

Mitre link : CVE-2026-18750

CVE.ORG link : CVE-2026-18750


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key