CVE-2026-35407 Details
Description
Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a business-logic and authorization flaw was found in the account email change workflow, the confirmation flow did not verify that the email change confirmation token was issued for the given authenticated user. As a result, a valid email-change token generated for one account can be replayed while authenticated as a different account. The second account’s email address is then updated to the token's new_email, even though that token was never issued for that account. This vulnerability is fixed in 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118.
A business-logic and authorization flaw exists in Saleor's email change workflow. The issue is present in versions 2.10.0 prior to 3.23.0a3, as well as in versions 3.22.47, 3.21.54, and 3.20.118. The vulnerability arises because the confirmation flow does not verify that the email change token was issued for the authenticated user. This allows a valid token from one account to be reused on another account, changing the email address to one controlled by the attacker. This flaw can lead to unauthorized account access by allowing an attacker to hijack a user's email, facilitating a password reset and account recovery.
Users can update to Saleor versions 3.23.0a3, 3.22.47, 3.21.54, or 3.20.118 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-285 | Improper Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| saleor saleor | >= 2.10.0, < 3.20.118 >= 3.20.119, < 3.21.54 >= 3.22.0, < 3.22.47 3.23.0 3.23.0 a0 3.23.0 a1 3.23.0 a2 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 15, 2026 | Initial Analysis | [email protected] |
| Apr 10, 2026 | CVE Modified | CISA-ADP |
| Apr 8, 2026 | New CVE Received | [email protected] |