Improper Ownership Validation in Paymenter Webshop Solution
CVE-2026-44585

5.4MEDIUM

Key Information:

Vendor

Paymenter

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-44585?

The Paymenter webshop solution contains a security issue within its ticket creation endpoint that fails to enforce ownership validation for service identifiers. Authenticated users can exploit this vulnerability by altering the service ID in their requests, allowing them to create support tickets that reference services owned by other users. Although access to customer data or service contents is not granted directly through this flaw, the potential for support personnel to inadvertently interact with unrelated services exists. This vulnerability has been addressed in version 1.5.0 of Paymenter, which mitigates the risk associated with unauthorized ticket creation.

Affected Version(s)

Paymenter < 1.5.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.