« Volver al listado

CVE-2026-94462

Estado: Pendiente de análisisAlta (7.1)—

Spree is an open source e-commerce solution built with Ruby on Rails. From 5.4.0 until 5.4.4 and 5.5.4, PATCH /api/v3/store/carts/:id/associate in Spree::Api::V3::Store::CartsController#associate uses find_cart_for_association to locate a cart by prefixed_id but does not require a cart token or otherwise verify possession of the selected guest cart. An authenticated customer can derive reversible prefixed cart IDs, associate an eligible guest cart with the attacker's account, and receive billing and shipping address data from the cart. Exploitation requires a guest cart with address data on a store that does not require login for checkout, and reassignment can also disrupt the guest's in-progress cart. This issue is fixed in versions 5.4.4 and 5.5.4.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Autenticación requerida (PR:L) para acceder a endpoint API expuesto sin validación de posesión de carrito. Lee datos sensibles (direcciones) e interrumpe carritos de terceros.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-94462",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-94462",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-09-22T19:20:02.955046Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4.2,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "spree",
          "product": "spree",
          "versions": [
            {
              "status": "affected",
              "version": ">= 5.4.0, < 5.4.4"
            },
            {
              "status": "affected",
              "version": ">= 5.5.0, < 5.5.4"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-09-22T19:16:59.497",
  "references": [
    {
      "url": "https://github.com/spree/spree/commit/8834230a1f47bb5988f23f45dbd162776cf592bd",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/spree/spree/commit/af0d1a2d582a60d179de65b7d3ea024cb26426a8",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/spree/spree/pull/14314",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/spree/spree/releases/tag/v5.4.4",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/spree/spree/releases/tag/v5.5.4",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/spree/spree/security/advisories/GHSA-4825-p4xm-pcf2",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/spree/spree/security/advisories/GHSA-4825-p4xm-pcf2",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-639"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Spree is an open source e-commerce solution built with Ruby on Rails. From 5.4.0 until 5.4.4 and 5.5.4, PATCH /api/v3/store/carts/:id/associate in Spree::Api::V3::Store::CartsController#associate uses find_cart_for_association to locate a cart by prefixed_id but does not require a cart token or otherwise verify possession of the selected guest cart. An authenticated customer can derive reversible prefixed cart IDs, associate an eligible guest cart with the attacker's account, and receive billing and shipping address data from the cart. Exploitation requires a guest cart with address data on a store that does not require login for checkout, and reassignment can also disrupt the guest's in-progress cart. This issue is fixed in versions 5.4.4 and 5.5.4."
    }
  ],
  "lastModified": "2026-09-23T18:12:04.247",
  "sourceIdentifier": "security-advisories@github.com"
}