Authenticated Insecure Direct Object Reference in Spree E-commerce Solution
CVE-2026-22588

6.5MEDIUM

Key Information:

Vendor

Spree

Status
Vendor
CVE Published:
8 January 2026

What is CVE-2026-22588?

A vulnerability in Spree allows authenticated users to exploit an Insecure Direct Object Reference (IDOR) by modifying existing orders to access other users' address information. This occurs when users manipulate address identifiers in their requests, leading the server to incorrectly associate the response with the attacker's order. Thorough remedial measures have been implemented in versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5 to mitigate this issue and enhance overall data security.

Affected Version(s)

spree >= 5.2.0, < 5.2.5 < 5.2.0, 5.2.5

spree >= 5.1.0, < 5.1.9 < 5.1.0, 5.1.9

spree >= 5.0.0, < 5.0.7 < 5.0.0, 5.0.7

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.