PT-2026-68023 · Crafter · Crater
CVSS v3.1
8.3
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Crater (affected versions not specified)
Description
An authorization bypass exists where the software fails to enforce company-ownership checks within the CustomerPolicy for view, update, and delete operations. While other policies verify both a Bouncer ability and the
company id of the user, the customer-related checks only verify the general ability. Additionally, route-model-bound customer lookups and the deleteCustomers() function are unscoped, as they use self::find($id) without a company filter. This allows an authenticated user from one company to read, reassign, or delete customer records belonging to another company, which also triggers the cascading deletion of associated invoices and payments.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Crater