Executive brief
VINCE is a web-based platform used by the CERT Coordination Center to manage coordinated vulnerability disclosure between vendors and security researchers. The vulnerability allows case members to retrieve confidential case artefacts (such as vulnerability details and technical materials) uploaded by coordinators before they have been intentionally released to other participants — potentially exposing sensitive, embargoed disclosure information to vendors prematurely.
Technical details
The vulnerability is an authorization bypass in the type=track endpoint that checks only whether the requesting user is a member of the case (_is_my_case) but fails to verify the VinceTrackAttachment.shared flag. An attacker with membership in a case can retrieve any non-shared case artefact by providing its UUID, even if that artefact was uploaded by a coordinator and marked confidential. The attack requires network access to the VINCE web platform and valid case membership. This bypass allows unauthorized disclosure of not-yet-released coordinator material (vulnerability reports, technical analysis, embargo agreements) to vendors participating in the case.
Affected products
- CERT/CC VINCE 3.0.44 and earlier
Timeline
- 2026-08-12: disclosed: CVE published on NVD
- 2026-08-13: patched: Fix merged in PR #235 (version 3.0.44 or later)