Account Ownership Vulnerability in Saleor E-Commerce Platform
CVE-2026-44472

8.1HIGH

Key Information:

Vendor

Saleor

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-44472?

This vulnerability in the Saleor e-commerce platform arises from its account activation flow, which incorrectly assumes that email verification alone is sufficient to establish account ownership. As a result, an attacker can exploit this weakness by creating an account using a victim's email address before they register. If the victim activates their account via the link sent to that email, the attacker can then merge the victim's anonymous commerce data with their account, gaining unauthorized access to sensitive information such as order history and personal identification data. The issue has been addressed in subsequent releases, enforcing password confirmations and disabling automatic data merging by default.

Affected Version(s)

saleor >= 2.10.0rc1, < 3.21.67 < 2.10.0rc1, 3.21.67

saleor >= 3.22.0-a.0, < 3.22.63 < 3.22.0-a.0, 3.22.63

saleor >= 3.23.0-a.0, < 3.23.22 < 3.23.0-a.0, 3.23.22

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.