A vulnerability described as problematic has been identified in CERT/CC VINCE up to 3.0.43. The affected element is the function
ModifyEmailNotifications of the file vinny/views.py of the component Email Notification. Executing a manipulation can lead to authorization bypass.
This vulnerability is handled as CVE-2026-18750. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.