PT-2026-31392 · Saleor · Saleor
Published
2026-04-08
·
Updated
2026-04-08
·
CVE-2026-35407
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Saleor versions 2.10.0 through 3.22.47, 3.21.54, and 3.20.118
Description
A business-logic and authorization flaw exists in the account email change workflow. The confirmation flow does not verify that the email change confirmation token was issued for the authenticated user. A valid email-change token generated for one account can be replayed while authenticated as a different account, leading to unauthorized email address modification. The
new email within the token is used to update the second account’s email address, even if the token was not originally intended for that account.Recommendations
Update to Saleor version 3.23.0a3 or later.
Update to Saleor version 3.22.47 or later.
Update to Saleor version 3.21.54 or later.
Update to Saleor version 3.20.118 or later.
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Saleor