PT-2026-4536 · Saleor · Saleor
Nyankiyoshi
·
Published
2026-01-23
·
Updated
2026-01-24
·
CVE-2026-24136
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Saleor versions 3.2.0 through 3.20.109
Saleor versions 3.21.0-a.0 through 3.21.44
Saleor versions 3.22.0-a.0 through 3.22.28
Description
Saleor, an e-commerce platform, is affected by an Insecure Direct Object Reference (IDOR) issue. This allows unauthenticated actors to extract sensitive information in plain text. Orders created before Saleor 3.2.0 may have Personally Identifiable Information (PII) exfiltrated. The issue allows unauthorized access to data through direct object references.
Recommendations
Update to Saleor version 3.22.29.
Update to Saleor version 3.21.45.
Update to Saleor version 3.20.110.
Temporarily block non-staff users from fetching order information using the
order() GraphQL query with a Web Application Firewall (WAF).Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Saleor