Access Control Flaw in CubeCart E-commerce Platform by CubeCart
CVE-2026-54648

6.5MEDIUM

Key Information:

Vendor

Cubecart

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-54648?

CubeCart, a popular e-commerce solution, contains an access control vulnerability within its GDPR tools. Prior to version 6.7.5, the system improperly relies on page-level permissions, allowing an authenticated administrator with merely read-only customer access to perform actions they should not have permissions for. These include purging and deleting customer records, including accounts without orders and guest accounts, leading to potential data integrity issues and compromising the availability of customer information. This vulnerability was addressed in version 6.7.5, urging all users to upgrade promptly to safeguard their data.

Affected Version(s)

v6 < 6.7.5

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.