Cubecart · Cubecart · CVE-2026-54648
**Name of the Vulnerable Software and Affected Versions**
CubeCart versions prior to 6.7.5
**Description**
An authorization bypass exists in the GDPR tools located in the `admin/sources/customers.gdpr.inc.php` file. The system relies on page-level `CC PERM READ` access and fails to require `CC PERM DELETE` for the `purge`, `no order purge`, and `delete guests` commands. Consequently, an authenticated administrator with only read-only customer privileges can directly invoke these backend actions to bypass interface restrictions and irreversibly delete customer records, accounts without orders, or guest accounts, which compromises data integrity and availability.
**Recommendations**
Update to version 6.7.5.