PT-2026-68023 · Crafter · Crater

·

CVE-2026-55739

·

Published

2026-08-05

·

Updated

2026-08-29

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Crater (affected versions not specified)
Description An authorization bypass exists where the software fails to enforce company-ownership checks within the CustomerPolicy for view, update, and delete operations. While other policies verify both a Bouncer ability and the company id of the user, the customer-related checks only verify the general ability. Additionally, route-model-bound customer lookups and the deleteCustomers() function are unscoped, as they use self::find($id) without a company filter. This allows an authenticated user from one company to read, reassign, or delete customer records belonging to another company, which also triggers the cascading deletion of associated invoices and payments.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55739

Affected Products

Crater