The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-crafted request to bypass the login page, access other users' credentials, take over other user accounts, access sensitive PII, and dump other information from the database.
References
| Link | Resource |
|---|---|
| https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-204-01.json | Third Party Advisory |
| https://www.cve.org/CVERecord?id=CVE-2026-63359 | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-07-23 20:17
Updated : 2026-08-26 13:47
NVD link : CVE-2026-63359
Mitre link : CVE-2026-63359
CVE.ORG link : CVE-2026-63359
JSON object : View
Products Affected
equifax
- victim_information_notification_exchange
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
