Vulnerability Description
Saleor is an e-commerce platform. From 3.14.67 until 3.21.67, 3.22.63, and 3.23.22, a broken authorization check in saleor/permission/utils.py can incorrectly authorize unauthenticated GraphQL requests. The flaw permits anonymous callers to use the channelUpdate() mutation to change channel order settings such as allowUnpaidOrders even when the response reports PermissionDenied. The same permission utility can expose hidden objects through the pageType() and translation() queries, including attributes whose visibleInStorefront field is false and that should be visible only to users with management permissions. This issue is fixed in versions 3.21.67, 3.22.63, and 3.23.22.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/saleor/saleor/commit/11efb4e9ea76942cf142bc01de8846cbaf764465
- https://github.com/saleor/saleor/commit/580b93b6e0faef7800e667f0c3bc507d3ef6f5f5
- https://github.com/saleor/saleor/commit/9b1f59b3ed86c3fad3ce071639cf434c1ab94a85
- https://github.com/saleor/saleor/commit/afd1ddd13b79e78db4e05f846b1f159078c50417
- https://github.com/saleor/saleor/releases/tag/3.21.67
- https://github.com/saleor/saleor/releases/tag/3.22.63
- https://github.com/saleor/saleor/releases/tag/3.23.22
- https://github.com/saleor/saleor/security/advisories/GHSA-xqqq-qhgq-gx53
FAQ
What is CVE-2026-48744?
CVE-2026-48744 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Saleor is an e-commerce platform. From 3.14.67 until 3.21.67, 3.22.63, and 3.23.22, a broken authorization check in saleor/permission/utils.py can incorrectly authorize unauthenticated GraphQL request...
How severe is CVE-2026-48744?
CVE-2026-48744 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-48744?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.