Weak Order Identifier Generation in Isotope eCommerce by Isotope
CVE-2026-96599

8.2HIGH

Key Information:

Vendor

Isotope

Vendor
CVE Published:
23 September 2026

What is CVE-2026-96599?

Isotope eCommerce versions up to 2.9.10 utilize a weak method for generating order identifiers, relying on the uniqid() function rather than a cryptographically secure alternative. This vulnerability permits unauthorized attackers to deduce order identifiers. In addition, the lack of proper ownership verification for guest orders enables these attackers to retrieve sensitive information related to orders, such as billing addresses, customer details, and purchased files, by manipulating the uid parameter. This poses significant risks for users, as their private information could easily be compromised.

Affected Version(s)

isotope-core 0 <= 2.9.10

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ikram-4
.