Unauthorized Cart Association in Spree E-commerce Platform
CVE-2026-94462
7.1HIGH
What is CVE-2026-94462?
The Spree e-commerce framework versions 5.4.0 through 5.5.4 exhibit a flaw in the cart association functionality. The affected endpoint allows authenticated users to retrieve and associate guest carts without the required verification processes. As a result, attackers can exploit this flaw to access sensitive billing and shipping information stored in guest carts. This specific vulnerability can lead to data exposure and disruption of the user's cart session, particularly on stores that do not enforce login procedures for checkout. The issue has been addressed in subsequent releases of the Spree platform.
Affected Version(s)
spree >= 5.4.0, < 5.4.4 < 5.4.0, 5.4.4
spree >= 5.5.0, < 5.5.4 < 5.5.0, 5.5.4
