CVE Explorer
CVE-2026-25741
Zulip is an open-source team collaboration tool. Prior to commit bf28c82dc9b1f630fa8e9106358771b20a0040f7, the API endpoint for creating a card update session during an upgrade flow was accessible to users with only organization member privileges. When the associated Stripe Checkout session is completed, the Stripe webhook updates the organization’s default payment method. Because no billing-specific authorization check is enforced, a regular (non-billing) member can change the organization’s pa
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"zulip","vendor":"zulip","versions":[{"status":"affected","version":"< bf28c82dc9b1f630fa8e9106358771b20a0040f7"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:df29d20d18b45088cd848dfc944542e188fe7c01f2d1469f51e9277f6641d54e · sha256:081e873543ea475e… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":7.1,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:df29d20d18b45088cd848dfc944542e188fe7c01f2d1469f51e9277f6641d54e · sha256:081e873543ea475e… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-863","description":"CWE-863: Incorrect Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:df29d20d18b45088cd848dfc944542e188fe7c01f2d1469f51e9277f6641d54e · sha256:081e873543ea475e… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/zulip/zulip/commit/bf28c82dc9b1f630fa8e9106358771b20a0040f7","tags":["x_refsource_MISC"],"url":"https://github.com/zulip/zulip/commit/bf28c82dc9b1f630fa8e9106358771b20a0040f7"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:df29d20d18b45088cd848dfc944542e188fe7c01f2d1469f51e9277f6641d54e · sha256:081e873543ea475e… · /containers/cna/references/1
{"name":"https://github.com/zulip/zulip/security/advisories/GHSA-vhhx-84f7-rc8j","tags":["x_refsource_CONFIRM"],"url":"https://github.com/zulip/zulip/security/advisories/GHSA-vhhx-84f7-rc8j"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:df29d20d18b45088cd848dfc944542e188fe7c01f2d1469f51e9277f6641d54e · sha256:081e873543ea475e… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.