CVE detail
CVE-2026-18744 — CVE-2026-18744
Published 2026-08-12 · Modified 2026-08-12 · Source nvd
UNKNOWN
severity
CVSS-derived band
—
EPSS probability
exploitation probability, 30d
—
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Any authenticated case participant can fetch any OTHER vendor's CaseStatement + per-vul CaseMemberStatus by supplying that member's id — test_func only checks _is_my_case, not ownership of kwargs['member']. Bypasses share_status; leaks embargoed vendor affected/not-affected + statement text cross-tenant.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References