← Back

CVE-2026-22589

nvd nist
Published: Jan 10, 2026Modified: Jan 22, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: security-advisories@github.com (Secondary)

Description

Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5, an Unauthenticated Insecure Direct Object Reference (IDOR) vulnerability was identified that allows an unauthenticated attacker to access guest address information without supplying valid credentials or session cookies. This issue has been patched in versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5.

Affected (4)

Products: Spreecommerce: Spree
1 product
Spree
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Spreecommerce
Before 4.10.2
From 5.0.0 to 5.0.7
From 5.1.0 to 5.1.9
From 5.2.0 to 5.2.5

References (6)

Timeline

No history available yet.