CVE-2026-44472

Source
https://cve.org/CVERecord?id=CVE-2026-44472
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44472.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-44472
Aliases
  • GHSA-6whj-8p3f-2xqp
Published
2026-08-18T17:11:42Z
Modified
2026-08-20T03:54:18Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N CVSS Calculator
Summary
Saleor: Account pre-hijacking vulnerability due to unverified anonymous order merge
Details

Saleor is an e-commerce platform. From 2.10.0rc1 until 3.21.67, 3.22.63, and 3.23.22, the account activation flow treats email verification as sufficient proof of account ownership and automatically associates anonymous commerce data with the newly activated account. An attacker can use accountRegister to create an account with a victim's email address before the victim registers. If the victim follows the activation link sent to that mailbox, Saleor activates the attacker-created account and saleor/graphql/account/mutations/account/confirm_account.py can merge anonymous orders and gift-card data for the same email address without requiring the account password or another authentication factor. The attacker can then access the merged order history and personal data, including names, addresses, and phone numbers. The patched supported lines disable automatic merging by default, while the redesigned 3.24.0 flow requires password confirmation before anonymous objects are linked. This issue is fixed in versions 3.21.67, 3.22.63, and 3.23.22.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-287"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44472.json"
}
References

Affected packages

Git / github.com/saleor/saleor

Affected ranges

Type
GIT
Repo
https://github.com/saleor/saleor
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "2.10.0rc1"
        },
        {
            "fixed": "3.21.67"
        },
        {
            "introduced": "3.22.0-a.0"
        },
        {
            "fixed": "3.22.63"
        },
        {
            "introduced": "3.23.0-a.0"
        },
        {
            "fixed": "3.23.22"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

2.*
2.0.0
2.1.0
2.10.0
2.10.0-rc.1
2.10.0-rc.2
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
Other
3-23-11-refresh
3.*
3.0.0-a.0
3.11.0-a.0
3.12.0-a.0
3.13.0-a.0
3.14.67
3.14.84
3.15.0-a.0
3.15.41
3.16.0-a.0
3.16.42
3.17.0-a.0
3.17.69
3.18.0-a.0
3.19.0-a.0
3.2.0
3.21.0
3.21.0-a.0
3.21.0-a.4
3.21.0-a.5
3.21.0-a.6
3.21.1
3.21.10
3.21.11
3.21.12
3.21.13
3.21.14
3.21.15
3.21.16
3.21.17
3.21.18
3.21.19
3.21.2
3.21.20
3.21.21
3.21.22
3.21.23
3.21.24
3.21.25
3.21.26
3.21.27
3.21.28
3.21.29
3.21.3
3.21.30
3.21.31
3.21.32
3.21.33
3.21.34
3.21.35
3.21.36
3.21.37
3.21.38
3.21.39
3.21.4
3.21.40
3.21.41
3.21.42
3.21.43
3.21.44
3.21.45
3.21.46
3.21.47
3.21.48
3.21.49
3.21.5
3.21.50
3.21.51
3.21.52
3.21.53
3.21.54
3.21.55
3.21.56
3.21.56-rc.1
3.21.56-rc.2
3.21.57
3.21.58
3.21.59
3.21.6
3.21.60
3.21.61
3.21.62
3.21.63
3.21.64
3.21.65
3.21.66
3.21.7
3.21.8
3.21.9
3.22.0
3.22.0-a.0
3.22.0-a.3
3.22.0-a.4
3.22.1
3.22.10
3.22.11
3.22.12
3.22.13
3.22.14
3.22.15
3.22.16
3.22.17
3.22.18
3.22.19
3.22.2
3.22.20
3.22.21
3.22.22
3.22.23
3.22.24
3.22.25
3.22.26
3.22.27
3.22.28
3.22.29
3.22.3
3.22.30
3.22.31
3.22.32
3.22.33
3.22.34
3.22.35
3.22.36
3.22.37
3.22.38
3.22.39
3.22.4
3.22.40
3.22.41
3.22.42
3.22.43
3.22.44
3.22.45
3.22.46
3.22.47
3.22.48
3.22.49
3.22.5
3.22.50
3.22.51
3.22.52
3.22.53
3.22.54
3.22.55
3.22.56
3.22.57
3.22.58
3.22.59
3.22.6
3.22.60
3.22.61
3.22.62
3.22.7
3.22.8
3.22.9
3.23.0
3.23.0-a.0
3.23.0-a.1
3.23.0-a.2
3.23.0.a.3
3.23.1
3.23.10
3.23.11
3.23.12
3.23.13
3.23.14
3.23.15
3.23.16
3.23.17
3.23.18
3.23.19
3.23.2
3.23.20
3.23.21
3.23.3
3.23.4
3.23.5
3.23.6
3.23.7
3.23.8
3.23.9
v2016.*
v2016.07.0
v2017.*
v2017.02.0
v2017.02.1
v2017.03.0
v2017.03.1
v2017.03.2
v2017.03.3
v2017.03.4
v2017.07.0
v2017.09
v2017.10
v2017.11
v2017.12
v2017.12.1
v2018.*
v2018.01
v2018.02
v2018.03
v2018.04
v2018.05
v2018.06
v2018.08
v2018.09

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44472.json"