Improper Ownership Validation in Paymenter Webshop Solution
CVE-2026-44585
5.4MEDIUM
What is CVE-2026-44585?
The Paymenter webshop solution contains a security issue within its ticket creation endpoint that fails to enforce ownership validation for service identifiers. Authenticated users can exploit this vulnerability by altering the service ID in their requests, allowing them to create support tickets that reference services owned by other users. Although access to customer data or service contents is not granted directly through this flaw, the potential for support personnel to inadvertently interact with unrelated services exists. This vulnerability has been addressed in version 1.5.0 of Paymenter, which mitigates the risk associated with unauthorized ticket creation.
Affected Version(s)
Paymenter < 1.5.0
