Information Disclosure in Vendure Open-Source Headless Commerce Platform
CVE-2026-63461

5.3MEDIUM

Key Information:

Vendor

Vendurehq

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-63461?

The Vendure open-source headless commerce platform contains a vulnerability that allows unauthenticated users to exploit the public Shop API. Prior to version 3.6.5, the API's products, collections, and facets queries improperly handled visibility guards in conjunction with filters provided by callers. Specifically, when using the 'OR' operator for filters, unauthorized access to hidden entities could occur, resulting in the potential retrieval of disabled products and private collections or facets. This issue has been addressed in version 3.6.5, reinforcing the integrity of the API.

Affected Version(s)

vendure >= 1.0.0, < 3.6.5

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.