PT-2026-95156 · Cubecart · Cubecart

·

CVE-2026-54648

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions CubeCart versions prior to 6.7.5
Description An authorization bypass exists in the GDPR tools located in the admin/sources/customers.gdpr.inc.php file. The system relies on page-level CC PERM READ access and fails to require CC PERM DELETE for the purge, no order purge, and delete guests commands. Consequently, an authenticated administrator with only read-only customer privileges can directly invoke these backend actions to bypass interface restrictions and irreversibly delete customer records, accounts without orders, or guest accounts, which compromises data integrity and availability.
Recommendations Update to version 6.7.5.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54648
GHSA-R376-2WR5-G9QX

Affected Products

Cubecart