Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a business-logic and authorization flaw was found in the account email change workflow, the confirmation flow did not verify that the email change confirmation token was issued for the given authenticated user. As a result, a valid email-change token generated for one account can be replayed while authenticated as a different account. The second account’s email address is then updated to the token's new_email, even though that token was never issued for that account. This vulnerability is fixed in 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118.
History

Wed, 15 Apr 2026 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*
cpe:2.3:a:saleor:saleor:3.23.0:*:*:*:*:*:*:*
cpe:2.3:a:saleor:saleor:3.23.0:a0:*:*:*:*:*:*
cpe:2.3:a:saleor:saleor:3.23.0:a1:*:*:*:*:*:*
cpe:2.3:a:saleor:saleor:3.23.0:a2:*:*:*:*:*:*

Fri, 10 Apr 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Saleor
Saleor saleor
Vendors & Products Saleor
Saleor saleor

Wed, 08 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Description Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a business-logic and authorization flaw was found in the account email change workflow, the confirmation flow did not verify that the email change confirmation token was issued for the given authenticated user. As a result, a valid email-change token generated for one account can be replayed while authenticated as a different account. The second account’s email address is then updated to the token's new_email, even though that token was never issued for that account. This vulnerability is fixed in 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118.
Title Saleor has Cross-Account Email Change via Unbound Confirmation Token
Weaknesses CWE-285
References
Metrics cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2026-04-08T17:24:39.716Z

Updated: 2026-04-10T20:36:19.733Z

Reserved: 2026-04-02T17:03:42.075Z

Link: CVE-2026-35407

cve-icon Vulnrichment

Updated: 2026-04-10T20:36:14.051Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-08T19:25:24.040

Modified: 2026-04-15T17:51:20.827

Link: CVE-2026-35407

cve-icon Redhat

No data.