Concurrency Vulnerability in Paymenter Webshop Solution
CVE-2026-71537
6.5MEDIUM
What is CVE-2026-71537?
Paymenter, a free and open-source webshop solution, contains a concurrency vulnerability that allows authenticated customers with downgradeable services to exploit the upgrade mechanism. Specifically, before version 1.5.7, multiple concurrent downgrade requests can create individual upgrade records without proper database transactions. This flaw enables the same account credit balance to be falsely incremented, potentially leading to multiple unauthorized refunds from a single transaction. The issue was resolved in version 1.5.7, which implements necessary transaction locks to prevent these malicious activities.
Affected Version(s)
Paymenter < 1.5.7
