{ "document": { "category": "csaf_vex", "csaf_version": "2.0", "lang": "en-US", "publisher": { "category": "coordinator", "contact_details": "https://www.cisa.gov/report", "issuing_authority": "CISA", "name": "CISA", "namespace": "https://www.cisa.gov/" }, "title": "Appriss Insights VINE Application SQL Injection", "tracking": { "current_release_date": "2026-08-04T16:33:52Z", "generator": { "engine": { "name": "VINCE-NT", "version": "1.15.0+build.101" } }, "id": "VA-26-204-01", "initial_release_date": "2026-07-23T18:12:13Z", "status": "final", "version": "2.0.0", "revision_history": [ { "number": "2.0.0", "summary": "Added fixed date and 'exclusively-hosted-service' tag", "date": "2026-08-04T16:33:52Z" }, { "number": "1.0.0", "summary": "Initial publication", "date": "2026-07-23T18:12:13Z" } ] }, "distribution": { "tlp": { "label": "WHITE" } }, "notes": [ { "text": "All information products included in [https://github.com/cisagov/CSAF/tree/develop/csaf_files/IT/white](https://github.com/cisagov/CSAF/tree/develop/csaf_files/IT/white) are provided \\\"as is\\\" for informational purposes only. The Department of Homeland Security (DHS) does not provide any warranties of any kind regarding any information contained within. DHS does not endorse any commercial product or service, referenced in this product or otherwise. Further dissemination of this product is governed by the Traffic Light Protocol (TLP) marking in the header. For more information about TLP, see [https://us-cert.cisa.gov/tlp/](https://us-cert.cisa.gov/tlp/).", "title": "Legal Notice", "category": "legal_disclaimer" }, { "text": "Worldwide", "title": "Countries and Areas Deployed", "category": "other" }, { "text": "Information Technology", "title": "Critical Infrastructure Sectors", "category": "other" }, { "text": "The Appriss Insights (Equifax) VINE applications allow an unauthenticated attacker to send a specially-crafted request to bypass the login page, access other users' credentials, take over other user accounts, access sensitive PII, and dump other information from the database.", "title": "Risk Evaluation", "category": "summary" }, { "text": "Use most recent available version of VINE.", "title": "Recommended Practices", "category": "general" }, { "text": "United States", "title": "Company Headquarters Location", "category": "other" } ], "references": [ { "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-204-01.json", "summary": "Vulnerability Advisory VA-26-204-01 CSAF", "category": "self" } ] }, "product_tree": { "branches": [ { "category": "vendor", "name": "Appriss Insights", "branches": [ { "category": "product_name", "name": "Victim Information Notification Exchange (VINE)", "branches": [ { "category": "product_version_range", "name": "<2026-05-07", "product": { "name": "Appriss Insights Victim Information Notification Exchange (VINE) <2026-05-07", "product_id": "CSAFPID-0001" } }, { "category": "product_version", "name": "2026-05-07", "product": { "name": "Appriss Insights Victim Information Notification Exchange (VINE) 2026-05-07", "product_id": "CSAFPID-0002" } } ] } ] } ] }, "vulnerabilities": [ { "cve": "CVE-2026-63359", "cwe": { "id": "CWE-89", "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" }, "notes": [ { "category": "summary", "text": "The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-crafted request to bypass the login page, access other users' credentials, take over other user accounts, access sensitive PII, and dump other information from the database.", "title": "Description" }, { "category": "details", "title": "SSVC", "text": "SSVCv2/E:N/A:Y/T:T/2026-07-13T19:39:57Z/" } ], "title": "Appriss Insights VINE SQLI", "product_status": { "known_affected": [ "CSAFPID-0001" ], "fixed": [ "CSAFPID-0002" ] }, "references": [ { "category": "external", "summary": "www.cve.org", "url": "https://www.cve.org/CVERecord?id=CVE-2026-63359" }, { "category": "external", "summary": "raw.githubusercontent.com", "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-204-01.json" } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "CSAFPID-0001" ] } ], "remediations": [ { "category": "vendor_fix", "details": "Fixed 2026-05-07.", "product_ids": [ "CSAFPID-0001" ], "date": "2026-05-07T00:00:00Z" }, { "category": "vendor_fix", "details": "Fixed 2026-05-07.", "product_ids": [ "CSAFPID-0002" ], "date": "2026-05-07T00:00:00Z" } ], "acknowledgments": [ { "organization": "CISA", "names": [ "Adam Rose" ] } ], "release_date": "2026-07-23T00:00:00Z" } ] }