Unauthorized Cart Association in Spree E-commerce Platform
CVE-2026-94462

7.1HIGH

Key Information:

Vendor

Spree

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-94462?

The Spree e-commerce framework versions 5.4.0 through 5.5.4 exhibit a flaw in the cart association functionality. The affected endpoint allows authenticated users to retrieve and associate guest carts without the required verification processes. As a result, attackers can exploit this flaw to access sensitive billing and shipping information stored in guest carts. This specific vulnerability can lead to data exposure and disruption of the user's cart session, particularly on stores that do not enforce login procedures for checkout. The issue has been addressed in subsequent releases of the Spree platform.

Affected Version(s)

spree >= 5.4.0, < 5.4.4 < 5.4.0, 5.4.4

spree >= 5.5.0, < 5.5.4 < 5.5.0, 5.5.4

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.