Executive brief
The VINE application, used to provide victims of crime with information about custody status and court cases, contains a critical security flaw. An unauthorized person can bypass the login screen to access sensitive personal information, steal user credentials, and take over accounts. This could lead to a massive data breach of private victim information and a total loss of system integrity.
Technical details
A critical SQL injection vulnerability (CWE-89) exists in the Appriss Insights VINE application. An unauthenticated remote attacker can exploit this by sending specially crafted network requests to the application. Successful exploitation allows the attacker to bypass authentication mechanisms, retrieve plaintext credentials, and perform a full database dump. This provides the attacker with unauthorized access to sensitive Personally Identifiable Information (PII) and the ability to take over arbitrary user accounts. The vulnerability is exploitable over the network without any user interaction or prior privileges.
Affected products
- Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) All versions affected
Timeline
- 2026-07-23: disclosed
- 2026-07-23: advisory