CVE Explorer
CVE-2026-24136
Saleor is an e-commerce platform. Versions 3.2.0 through 3.20.109, 3.21.0-a.0 through 3.21.44 and 3.22.0-a.0 through 3.22.28 have a n Insecure Direct Object Reference (IDOR) vulnerability that allows unauthenticated actors to extract sensitive information in plain text. Orders created before Saleor 3.2.0 could have PIIs exfiltrated. The issue has been patched in Saleor versions: 3.22.29, 3.21.45, and 3.20.110. To workaround, temporarily block non-staff users from fetching order information (the
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"saleor","vendor":"saleor","versions":[{"status":"affected","version":">= 3.22.0-a.0, < 3.22.29"},{"status":"affected","version":">= 3.21.0-a.0, < 3.21.45"},{"status":"affected","version":">= 3.2.0, < 3.20.110"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:12edbeff4f4d1499900a354a584917f6c6d8e14819bf4dd52307229040f740cc · sha256:66df5c49ac45c664… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.7,"baseSeverity":"HIGH","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:12edbeff4f4d1499900a354a584917f6c6d8e14819bf4dd52307229040f740cc · sha256:66df5c49ac45c664… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-639","description":"CWE-639: Authorization Bypass Through User-Controlled Key","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:12edbeff4f4d1499900a354a584917f6c6d8e14819bf4dd52307229040f740cc · sha256:66df5c49ac45c664… · /containers/cna/problemTypes/0/descriptions/0
Source references
5 source assertions{"name":"https://github.com/saleor/saleor/commit/5dab1857fbb2801f74e2bfe86f307e4590d9d2fa","tags":["x_refsource_MISC"],"url":"https://github.com/saleor/saleor/commit/5dab1857fbb2801f74e2bfe86f307e4590d9d2fa"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:12edbeff4f4d1499900a354a584917f6c6d8e14819bf4dd52307229040f740cc · sha256:66df5c49ac45c664… · /containers/cna/references/1
{"name":"https://github.com/saleor/saleor/commit/718ce1b4fc3aef68eeac1aea0cf1d70a614ba6af","tags":["x_refsource_MISC"],"url":"https://github.com/saleor/saleor/commit/718ce1b4fc3aef68eeac1aea0cf1d70a614ba6af"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:12edbeff4f4d1499900a354a584917f6c6d8e14819bf4dd52307229040f740cc · sha256:66df5c49ac45c664… · /containers/cna/references/2
{"name":"https://github.com/saleor/saleor/commit/9bcd4f9000b189297eeb3ac88cc28c6c30229153","tags":["x_refsource_MISC"],"url":"https://github.com/saleor/saleor/commit/9bcd4f9000b189297eeb3ac88cc28c6c30229153"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:12edbeff4f4d1499900a354a584917f6c6d8e14819bf4dd52307229040f740cc · sha256:66df5c49ac45c664… · /containers/cna/references/3
{"name":"https://github.com/saleor/saleor/commit/aeaced8acb5e01055eddec584263f77e517d5944","tags":["x_refsource_MISC"],"url":"https://github.com/saleor/saleor/commit/aeaced8acb5e01055eddec584263f77e517d5944"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:12edbeff4f4d1499900a354a584917f6c6d8e14819bf4dd52307229040f740cc · sha256:66df5c49ac45c664… · /containers/cna/references/4
{"name":"https://github.com/saleor/saleor/security/advisories/GHSA-r6fj-f4r9-36gr","tags":["x_refsource_CONFIRM"],"url":"https://github.com/saleor/saleor/security/advisories/GHSA-r6fj-f4r9-36gr"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:12edbeff4f4d1499900a354a584917f6c6d8e14819bf4dd52307229040f740cc · sha256:66df5c49ac45c664… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.