PT-2026-56567 · Gumroad · Gumroad
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Gumroad versions prior to 2026.07.06.2
Description
Broken access control in the
PurchasesController allows authenticated sellers to manipulate purchase access for products belonging to other sellers. By sending PUT requests to the revoke access and undo revoke access actions, an attacker can modify the is access revoked status on arbitrary purchases. This occurs because the system fails to validate seller ownership, enabling the unauthorized revocation or restoration of buyer access to products the attacker does not own.Recommendations
Update to version 2026.07.06.2 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gumroad