PT-2026-66497 · Git+1 · Vendure

·

CVE-2026-67347

·

Published

2026-07-30

·

Updated

2026-07-30

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vendure versions prior to 3.7.2
Description An authorization bypass exists in the update methods of stock-location.service.ts and asset.service.ts. This issue allows channel-scoped administrators to modify data belonging to other tenants by providing global IDs of StockLocation or Asset entities from different channels. The flaw occurs because the system fails to perform proper channel isolation validation, enabling the overwriting of inventory locations or catalog assets across different tenants.
Recommendations Update to version 3.7.2 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67347

Affected Products

Vendure