CVE-2026-92809

Source
https://cve.org/CVERecord?id=CVE-2026-92809
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92809.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-92809
Published
2026-09-16T20:32:56Z
Modified
2026-09-24T03:30:30Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
PrestaShop psgdpr through 1.4.3 GDPR Log Forgery
Details

PrestaShop psgdpr versions through 1.4.3 fail to validate that GDPR consent log entries are attributed to the authenticated customer. Authenticated attackers can submit arbitrary customer identifiers to create forged consent records for other customers, corrupting audit logs.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-639"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92809.json"
}
References

Affected packages

Git / github.com/prestashop/psgdpr

Affected ranges

Type
GIT
Repo
https://github.com/prestashop/psgdpr
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "last_affected":  "1.4.3"
        },
        {
            "fixed":  "1.4.3"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

v1.*
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.3.0
v1.4.0
v1.4.1
v1.4.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92809.json"