Authenticated Insecure Direct Object Reference in Spree E-commerce Solution
CVE-2026-22588
6.5MEDIUM
What is CVE-2026-22588?
A vulnerability in Spree allows authenticated users to exploit an Insecure Direct Object Reference (IDOR) by modifying existing orders to access other users' address information. This occurs when users manipulate address identifiers in their requests, leading the server to incorrectly associate the response with the attacker's order. Thorough remedial measures have been implemented in versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5 to mitigate this issue and enhance overall data security.
Affected Version(s)
spree >= 5.2.0, < 5.2.5 < 5.2.0, 5.2.5
spree >= 5.1.0, < 5.1.9 < 5.1.0, 5.1.9
spree >= 5.0.0, < 5.0.7 < 5.0.0, 5.0.7
