PT-2026-56567 · Gumroad · Gumroad

·

CVE-2026-59805

·

Published

2026-07-08

·

Updated

2026-07-09

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Gumroad versions prior to 2026.07.06.2
Description Broken access control in the PurchasesController allows authenticated sellers to manipulate purchase access for products belonging to other sellers. By sending PUT requests to the revoke access and undo revoke access actions, an attacker can modify the is access revoked status on arbitrary purchases. This occurs because the system fails to validate seller ownership, enabling the unauthorized revocation or restoration of buyer access to products the attacker does not own.
Recommendations Update to version 2026.07.06.2 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59805

Affected Products

Gumroad