Missing Authentication in Chaskiq Allows Unauthenticated Access to Stripe Billing Portal
CVE-2026-72535
8.2HIGH
What is CVE-2026-72535?
A missing authentication vulnerability in Chaskiq allows unauthenticated remote attackers to exploit the stripeCustomerPortal GraphQL mutation. This vulnerability enables an attacker to create Stripe Billing Portal sessions for any tenant without needing credentials. By bypassing authentication checks, attackers can gain unauthorized access to manage and view subscription data associated with any tenant's Stripe account, resulting in potential data breaches and financial implications.
Affected Version(s)
Chaskiq 0 <= 46dfdd1
