Missing Authentication in Chaskiq Allows Unauthenticated Access to Stripe Billing Portal
CVE-2026-72535

8.2HIGH

Key Information:

Vendor

Chaskiq

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-72535?

A missing authentication vulnerability in Chaskiq allows unauthenticated remote attackers to exploit the stripeCustomerPortal GraphQL mutation. This vulnerability enables an attacker to create Stripe Billing Portal sessions for any tenant without needing credentials. By bypassing authentication checks, attackers can gain unauthorized access to manage and view subscription data associated with any tenant's Stripe account, resulting in potential data breaches and financial implications.

Affected Version(s)

Chaskiq 0 <= 46dfdd1

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bobur Abdugafforov (Mahadsec)
.