Concurrency Vulnerability in Paymenter Webshop Solution
CVE-2026-71537

6.5MEDIUM

Key Information:

Vendor

Paymenter

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-71537?

Paymenter, a free and open-source webshop solution, contains a concurrency vulnerability that allows authenticated customers with downgradeable services to exploit the upgrade mechanism. Specifically, before version 1.5.7, multiple concurrent downgrade requests can create individual upgrade records without proper database transactions. This flaw enables the same account credit balance to be falsely incremented, potentially leading to multiple unauthorized refunds from a single transaction. The issue was resolved in version 1.5.7, which implements necessary transaction locks to prevent these malicious activities.

Affected Version(s)

Paymenter < 1.5.7

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.