Ecommerce Software Vulnerability in CubeCart by CubeCart
CVE-2026-54643

5.4MEDIUM

Key Information:

Vendor

Cubecart

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-54643?

CubeCart, an ecommerce software platform, contains a vulnerability in its delete-note handler located in admin/sources/orders.index.inc.php. In versions prior to 6.7.5, this handler only checks for the presence of order_id and delete-note parameters, allowing authenticated administrators without order modification privileges to delete order-history notes by directly invoking the handler. This exposes operational records and audit trails to unauthorized deletion. The issue is resolved in version 6.7.5, which enhances permission checks for the deletion process.

Affected Version(s)

v6 < 6.7.5

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.