CVE-2026-24136

Source
https://cve.org/CVERecord?id=CVE-2026-24136
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-24136.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-24136
Aliases
  • GHSA-r6fj-f4r9-36gr
Published
2026-01-23T23:38:31.414Z
Modified
2026-03-01T02:56:56.139501Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Saleor has an Insecure Direct Object Reference (IDOR) in GraphQL API
Details

Saleor is an e-commerce platform. Versions 3.2.0 through 3.20.109, 3.21.0-a.0 through 3.21.44 and 3.22.0-a.0 through 3.22.28 have a n Insecure Direct Object Reference (IDOR) vulnerability that allows unauthenticated actors to extract sensitive information in plain text. Orders created before Saleor 3.2.0 could have PIIs exfiltrated. The issue has been patched in Saleor versions: 3.22.29, 3.21.45, and 3.20.110. To workaround, temporarily block non-staff users from fetching order information (the order() GraphQL query) using a WAF.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/24xxx/CVE-2026-24136.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-639"
    ]
}
References

Affected packages

Git / github.com/saleor/saleor

Affected ranges

Type
GIT
Repo
https://github.com/saleor/saleor
Events
Database specific
{
    "versions": [
        {
            "introduced": "3.22.0-a.0"
        },
        {
            "fixed": "3.22.29"
        }
    ]
}
Type
GIT
Repo
https://github.com/saleor/saleor
Events
Database specific
{
    "versions": [
        {
            "introduced": "3.21.0-a.0"
        },
        {
            "fixed": "3.21.45"
        }
    ]
}
Type
GIT
Repo
https://github.com/saleor/saleor
Events
Database specific
{
    "versions": [
        {
            "introduced": "3.2.0"
        },
        {
            "fixed": "3.20.110"
        }
    ]
}

Affected versions

3.*
3.11.0-a.0
3.12.0-a.0
3.13.0-a.0
3.14.67
3.15.0-a.0
3.15.41
3.16.0-a.0
3.16.42
3.17.0-a.0
3.18.0-a.0
3.19.0-a.0
3.2.0
3.20.0
3.20.0-a.0
3.20.0-a.1
3.20.1
3.20.10
3.20.100
3.20.101
3.20.102
3.20.103
3.20.104
3.20.105
3.20.106
3.20.107
3.20.108
3.20.109
3.20.11
3.20.12
3.20.13
3.20.14
3.20.15
3.20.16
3.20.17
3.20.18
3.20.19
3.20.2
3.20.20
3.20.21
3.20.22
3.20.23
3.20.24
3.20.25
3.20.26
3.20.27
3.20.28
3.20.29
3.20.3
3.20.30
3.20.31
3.20.32
3.20.33
3.20.34
3.20.35
3.20.36
3.20.37
3.20.38
3.20.39
3.20.4
3.20.40
3.20.41
3.20.42
3.20.43
3.20.44
3.20.45
3.20.46
3.20.47
3.20.48
3.20.49
3.20.5
3.20.50
3.20.51
3.20.52
3.20.53
3.20.54
3.20.55
3.20.56
3.20.57
3.20.58
3.20.59
3.20.6
3.20.60
3.20.61
3.20.62
3.20.63
3.20.64
3.20.65
3.20.66
3.20.67
3.20.68
3.20.69
3.20.7
3.20.70
3.20.71
3.20.72
3.20.73
3.20.74
3.20.75
3.20.76
3.20.77
3.20.78
3.20.79
3.20.8
3.20.80
3.20.81
3.20.82
3.20.83
3.20.84
3.20.85
3.20.86
3.20.87
3.20.88
3.20.89
3.20.9
3.20.90
3.20.91
3.20.92
3.20.93
3.20.94
3.20.95
3.20.96
3.20.97
3.20.98
3.20.99
3.21.0
3.21.0-a.0
3.21.0-a.4
3.21.0-a.5
3.21.0-a.6
3.21.1
3.21.10
3.21.11
3.21.12
3.21.13
3.21.14
3.21.15
3.21.16
3.21.17
3.21.18
3.21.19
3.21.2
3.21.20
3.21.21
3.21.22
3.21.23
3.21.24
3.21.25
3.21.26
3.21.27
3.21.28
3.21.29
3.21.3
3.21.30
3.21.31
3.21.32
3.21.33
3.21.34
3.21.35
3.21.36
3.21.37
3.21.38
3.21.39
3.21.4
3.21.40
3.21.41
3.21.42
3.21.43
3.21.44
3.21.5
3.21.6
3.21.7
3.21.8
3.21.9
3.22.0
3.22.0-a.0
3.22.0-a.3
3.22.0-a.4
3.22.1
3.22.10
3.22.11
3.22.12
3.22.13
3.22.14
3.22.15
3.22.16
3.22.17
3.22.18
3.22.19
3.22.2
3.22.20
3.22.21
3.22.22
3.22.23
3.22.24
3.22.25
3.22.26
3.22.27
3.22.28
3.22.3
3.22.4
3.22.5
3.22.6
3.22.7
3.22.8
3.22.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-24136.json"