PT-2026-22199 · Zulip+1 · Zulip+1
Odgrso
·
Published
2026-02-26
·
Updated
2026-03-03
·
CVE-2026-25741
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Zulip versions prior to commit bf28c82dc9b1f630fa8e9106358771b20a0040f7
Description
Zulip is a team collaboration tool. A flaw existed in the API endpoint used for creating a card update session during an upgrade process, allowing users with organization member privileges to access it. Upon completion of the associated Stripe Checkout session, the Stripe webhook would update the organization’s default payment method. A lack of billing-specific authorization checks allowed regular organization members to modify the organization’s payment method. This impacted the Zulip Cloud payment processing system. The issue was addressed with commit bf28c82dc9b1f630fa8e9106358771b20a0040f7. The API endpoint involved is '/api/card update session'. The vulnerable operation involves updating the organization’s default payment method via a Stripe webhook.
Recommendations
For Zulip Cloud deployments, upgrade to a version with commit bf28c82dc9b1f630fa8e9106358771b20a0040f7 or later.
Self-hosted deployments are no longer affected and do not require any action.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Stripe
Zulip