The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-crafted request to bypass the login page, access other users' credentials, take over other user accounts, access sensitive PII, and dump other information from the database.
History

Wed, 26 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Equifax
Equifax victim Information Notification Exchange
CPEs cpe:2.3:a:equifax:victim_information_notification_exchange:*:*:*:*:*:*:*:*
Vendors & Products Equifax
Equifax victim Information Notification Exchange

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Appriss Insights
Appriss Insights victim Information Notification Exchange (vine)
Vendors & Products Appriss Insights
Appriss Insights victim Information Notification Exchange (vine)

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-crafted request to bypass the login page, access other users' credentials, take over other user accounts, access sensitive PII, and dump other information from the database.
Title Appriss Insights VINE SQLI
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published: 2026-07-23T18:48:43.984Z

Updated: 2026-07-31T18:02:41.249Z

Reserved: 2026-07-16T14:56:43.960Z

Link: CVE-2026-63359

cve-icon Vulnrichment

Updated: 2026-07-27T18:06:34.036Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-23T20:17:20.367

Modified: 2026-08-26T13:47:47.070

Link: CVE-2026-63359

cve-icon Redhat

No data.